To create a BIOC rule with XQL query you must at a minimum filter on which field in order for it to be a valid BIOC rule?
To create a BIOC rule with XQL query, you must at a minimum filter on theevent_typefield in order for it to be a valid BIOC rule. The event_type field indicates the type of event that triggered the alert, such as PROCESS, FILE, REGISTRY, NETWORK, or USER_ACCOUNT. Filtering on this field helps you narrow down the scope of your query and focus on the relevant events for your use case. Other fields, such as causality_chain, endpoint_name, threat_event, are optional and can be used to further refine your query or display additional information in the alert.Reference:
Palo Alto Networks Certified Detection and Remediation Analyst (PCDRA) Study Guide, page 9
Palo Alto Networks Cortex XDR Documentation, BIOC Rule Query Syntax
Which two types of exception profiles you can create in Cortex XDR? (Choose two.)
Cortex XDR allows you to create two types of exception profiles: agent exception profiles and global exception profiles. Agent exception profiles apply to specific endpoints that are assigned to the profile. Global exception profiles apply to all endpoints in your network. You can use exception profiles to configure different types of exceptions, such as process exceptions, support exceptions, behavioral threat protection rule exceptions, local analysis rules exceptions, advanced analysis exceptions, or digital signer exceptions. Exception profiles help you fine-tune the security policies for your endpoints and reduce false positives.Reference:
Create an Agent Exception Profile
Create a Global Exception Profile
What license would be required for ingesting external logs from various vendors?
To ingest external logs from various vendors, you need a Cortex XDR Pro per TB license. This license allows you to collect and analyze logs from Palo Alto Networks and third-party sources, such as firewalls, proxies, endpoints, cloud services, and more. You can use the Log Forwarding app to forward logs from the Logging Service to an external syslog receiver. The Cortex XDR Pro per Endpoint license only supports logs from Cortex XDR agents installed on endpoints. The Cortex XDR Vendor Agnostic Pro and Cortex XDR Cloud per Host licenses do not exist.Reference:
Features by Cortex XDR License Type
Log Forwarding App for Cortex XDR Analytics
Which statement is true for Application Exploits and Kernel Exploits?
The ultimate goal of any exploit is to reach the kernel, which is the core component of the operating system that has the highest level of privileges and access to the hardware resources. Application exploits are attacks that target vulnerabilities in specific applications, such as web browsers, email clients, or office suites. Kernel exploits are attacks that target vulnerabilities in the kernel itself, such as memory corruption, privilege escalation, or code execution. Kernel exploits are more difficult to prevent and detect than application exploits, because they can bypass security mechanisms and hide their presence from the user and the system.Reference:
Palo Alto Networks Certified Detection and Remediation Analyst (PCDRA) Study Guide, page 8
Palo Alto Networks Cortex XDR Documentation, Exploit Protection Overview
Which license is required when deploying Cortex XDR agent on Kubernetes Clusters as a DaemonSet?
Cassi
2 days agoStaci
10 days agoMalinda
18 days agoShalon
25 days agoNichelle
1 month agoTwila
1 month agoCarmen
2 months agoBen
2 months agoSue
2 months agoMichael
2 months agoChu
3 months agoAlton
3 months agoTish
3 months agoFreeman
3 months agoTien
4 months agoLilli
4 months agoMarget
4 months agoAretha
4 months agoEmeline
5 months agoFredric
5 months agoEun
5 months agoFrank
5 months agoMirta
6 months agoLonny
6 months agoRoxane
6 months agoCarolann
6 months agoCaprice
8 months agoTanja
8 months agoBettina
9 months agoLino
9 months agoDevorah
10 months agoBlondell
10 months agoShannon
10 months agoTiera
11 months agoKrissy
11 months agoViola
12 months agoMiesha
1 year agoLynsey
1 year agoRaylene
1 year agoLavonna
1 year agoAnnice
1 year agoVenita
1 year agoAvery
1 year agoMaia
1 year agoLezlie
1 year agoNguyet
1 year agoRenato
1 year agoSabrina
1 year agoAmira
1 year agoBreana
1 year agoLauran
1 year agoMalika
1 year agoDemetra
1 year agoAleta
1 year agoMarnie
1 year agoSabra
1 year agoKaycee
1 year agoYoulanda
1 year agoJess
1 year agoRhea
1 year agoColetta
1 year agoElmer
1 year agoVirgilio
2 years agoCiara
2 years agoAlbina
2 years agoAleta
2 years agoTarra
2 years agoJoaquin
2 years agoGenevive
2 years agoDudley
2 years agoRebbecca
2 years agoFrance
2 years agoJeniffer
2 years ago