Paloalto Networks XSIAM-Engineer - Palo Alto Networks XSIAM Engineer
What should be considered when creating a custom incident domain?
What is the function of the "MODEL" section when creating a data model rule?
When activating the Cortex XSIAM tenant, how is the data at rest configured with AES 128 encryption?
How must Cloud Identity Engine be deployed and activated on Cortex XSIAM?
What is a key characteristic of a parsing rule in Cortex XSIAM?
Cortex XSIAM has not received any logs for 30 minutes from a Palo Alto Networks NGFW named "MainFW.†An engineer wants to create an alert for this scenario.
Correlation rule settings include:
Time Schedule: Every 30 minutes
Query Timeframe: 30 minutes
Action: Generate alert
Alert Name: No logs received from MainFW in the past 30 minutes
Which query should be used in the correlation rule?
A)

B)

C)

D)
What is the role of "in" in the query line below?
action_local_port in (1122, 2234)
