How can an administrator run a Cortex XSOAR playbook regularly at a specific time and day of the week?
Which action should an administrator take to create automated response actions when a user account is compromised? (Choose one answer)
Which Cortex XSIAM component uses machine learning to automatically build a baseline of "normal" behavior for every user and host in the network, and then provides a searchable profile of their historical activity and risk level?
What is the WildFire verdict on a sample that does not pose a direct security threat, but is shown to display obtrusive behavior?
During which phase of the NIST Incident Response lifecycle does a SOC team conduct a "Lessons Learned" meeting to improve future response efforts?
Which response action in Cortex XSIAM would be unavailable to a SOC analyst investigating an incident involving a Linux server?
An administrator needs to prevent users from connecting unauthorized USB flash drives to their corporate workstations to reduce the risk of data exfiltration. Which Cortex XDR feature should be configured?