Using the integrationContext object, how is data stored and retrieved between integration command runs in Cortex XSIAM?
In which two locations can correlation rules be monitored for errors? (Choose two.)
Which two requirements must be met for a Cortex XDR agent to successfully use the Broker VM as a download source for content updates? (Choose two.)
What is the primary benefit of setting the "--memory-swap" option to "-1" during Cortex XSIAM engine deployment?
A file for a support exception that needs to be updated locally on a Linux endpoint has been supplied.
Which cytool command will upload this support exception file to the endpoint?
A Cortex XSIAM engineer is implementing role-based access control (RBAC) and scope-based access control (SBAC) for users accessing the Cortex XSIAM tenant with the following requirements:
Users managing machines in Europe should be able to manage and control all endpoints and installations, create profiles and policies, view alerts, and initiate Live Terminal, but only for endpoints in the Europe region.
Users managing machines in Europe should not be able to create, modify, or delete new or existing user roles.
The Europe region endpoints are identified by both of the following:
Endpoint Tag = "Europe-Servers" and Endpoint Group = "Europe" for servers in Europe
Endpoint Group = "Europe" and Endpoint Tag = "Europe-Workstation" for workstations in Europe
Which two sets of implementation actions should the engineer take? (Choose two.)
Before initiating a malware scan action on a Linux workstation, an engineer notices that the Cortex XDR agent's operational status on the workstation is reporting as "partially protected." There have been no configuration changes made from the Cortex XSIAM server.
What are two explanations for this operational status? (Choose two.)
When Cortex XDR agents are on servers in a zone with no internet access, which configuration will keep them communicating with the platform?
Cortex XSIAM has not received any logs for 30 minutes from a Palo Alto Networks NGFW named "MainFW.” An engineer wants to create an alert for this scenario.
Correlation rule settings include:
Time Schedule: Every 30 minutes
Query Timeframe: 30 minutes
Action: Generate alert
Alert Name: No logs received from MainFW in the past 30 minutes
Which query should be used in the correlation rule?
A)

B)

C)

D)
While using the playbook debugger, an engineer attaches the context of an alert as test data.
What happens with respect to the interactions with the list objects via tasks in this scenario?
Which action is required to enable use of a custom script in an alert layout?
Based on the _raw_log and XQL query information below, what will be the result(s) of the temp_value?
