Paloalto Networks Palo Alto Networks System Engineer - Cortex Professional PSE-Cortex Question # 42 Topic 5 Discussion
PSE-Cortex Exam Topic 5 Question 42 Discussion:
Question #: 42
Topic #: 5
Which statement applies to the differentiation of Cortex XDR from security information and event management (SIEM)?
A.
SIEM has access to raw logs from agents, where Cortex XDR traditionally only gets alerts.
B.
Cortex XDR allows just logging into the console and out of the box the events were blocked as a proactive approach.
C.
Cortex XDR requires a large and diverse team of analysts and up to several weeks for simple actions like creating an alert.
D.
SIEM has been entirely designed and built as cloud-native, with the ability to stitch together cloud logs, on-premises logs, third-party logs, and endpoint logs.
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit