Which Cortex XSIAM feature uses machine learning to automatically group related alerts into a single, manageable incident to reduce alert fatigue?
Which statement explains the difference between the Cortex Identity Threat Detection and Response (ITDR) module and Identity Analytics in Cortex XSIAM?
What is a difference between cold storage and hot storage in Cortex?
Which metric is used by SOC management to measure the average "Dwell Time"—the duration between a successful compromise and the moment it is first identified by a security tool or analyst?
Which protocol is commonly used by Cortex XSOAR to automatically pull threat intelligence indicators from external TAXII servers?
Which component of Cortex XDR is designed to detect insider threats?
Which incident should a responder prioritize based on overall functional and informational impact to the company?
Which Cortex XDR component raises an alert when suspicious activity composed of multiple events is detected and deviates from established baseline behavior?
Which activities are facilitated through the War Room in Cortex XSOAR? (Choose one answer)
What is the function of a Causality View?
TESTED 19 Apr 2026