ExamGecko
Question list
Search
Search

Question 36 - PCDRA discussion

Report
Export

What license would be required for ingesting external logs from various vendors?

A.
Cortex XDR Pro per Endpoint
Answers
A.
Cortex XDR Pro per Endpoint
B.
Cortex XDR Vendor Agnostic Pro
Answers
B.
Cortex XDR Vendor Agnostic Pro
C.
Cortex XDR Pro per TB
Answers
C.
Cortex XDR Pro per TB
D.
Cortex XDR Cloud per Host
Answers
D.
Cortex XDR Cloud per Host
Suggested answer: C

Explanation:

To ingest external logs from various vendors, you need a Cortex XDR Pro per TB license. This license allows you to collect and analyze logs from Palo Alto Networks and third-party sources, such as firewalls, proxies, endpoints, cloud services, and more. You can use the Log Forwarding app to forward logs from the Logging Service to an external syslog receiver. The Cortex XDR Pro per Endpoint license only supports logs from Cortex XDR agents installed on endpoints. The Cortex XDR Vendor Agnostic Pro and Cortex XDR Cloud per Host licenses do not exist.Reference:

Features by Cortex XDR License Type

Log Forwarding App for Cortex XDR Analytics

SaaS Log Collection

asked 23/09/2024
Rachana Kesarkar
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first