CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 27: XSIAM-ENGINEER: Palo Alto Networks XSIAM Engineer

A security engineer notices that in the past week ingestion has spiked significantly. Upon investigating the anomaly, it is determined that a custom application developed in-house caused the spike. The custom application is sending syslog to the Broker VM Syslog Collector applet. The engineer consults with the SOC ana…

Nội dung câu hỏi

A security engineer notices that in the past week ingestion has spiked significantly. Upon investigating the anomaly, it is determined that a custom application developed in-house caused the spike. The custom application is sending syslog to the Broker VM Syslog Collector applet. The engineer consults with the SOC analyst, who determines that 90% of the logs from the custom application are not used. What can the engineer configure to reduce the ingestion?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Parsing rule to drop the unnecessary data at the Broker VM — đáp án hiện tại
  2. B. Data model rule to drop the unnecessary data
  3. C. Correlation rule on the Cortex XSIAM server to drop the unnecessary data
  4. D. Data model rule to map the useful data

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề