Which solution will minimize mean time to resolution (MTTR) when, as a result of previous malware infection, a company's Windows endpoint is suffering a small amount of file corruption and modified registry keys?
A security analyst is tuning Cortex XDR after a custom application, which uses the mshta.exe utility with a legitimate internal script, triggers a behavioral threat alert. The administrator must ensure the legitimate script runs without detection. Which set of criteria must be included in the new exception rule to prevent future false positives while maintaining protection against similar malicious activity?
During an incident response engagement, a forensic investigator discovers a persistent threat actor using a custom command-and- control (C2) protocol over port 53 (DNS). The existing SIEM logs show only generic DNS queries. To gain a comprehensive understanding of the adversary's TTPs (Tactics, Techniques, and Procedures), including their C2 infrastructure, exploit development, and motivation, and to proactively block future attacks, which combination of resources would be most beneficial?
Where can an administrator begin to grant a new non-SSO user access to a Cortex XDR tenant?
In Cortex XSOAR, which key function is fulfilled by content packs, distinguishing them from individual content items like scripts or playbooks?
Which two steps belong in the Cortex XSOAR incident lifecycle? (Choose two.)