ExamGecko
Question list
Search
Search

Question 77 - PCDRA discussion

Report
Export

What is the difference between presets and datasets in XQL?

A.
A dataset is a Cortex data lake data source only; presets are built-in data source.
Answers
A.
A dataset is a Cortex data lake data source only; presets are built-in data source.
B.
A dataset is a built-in or third-party source; presets group XDR data fields.
Answers
B.
A dataset is a built-in or third-party source; presets group XDR data fields.
C.
A dataset is a database; presets is a field.
Answers
C.
A dataset is a database; presets is a field.
D.
A dataset is a third-party data source; presets are built-in data source.
Answers
D.
A dataset is a third-party data source; presets are built-in data source.
Suggested answer: B

Explanation:

The difference between presets and datasets in XQL is that a dataset is a built-in or third-party data source, while a preset is a group of XDR data fields. A dataset is a collection of data that you can query and analyze using XQL. A dataset can be a Cortex data lake data source, such as endpoints, alerts, incidents, or network flows, or a third-party data source, such as AWS CloudTrail, Azure Activity Logs, or Google Cloud Audit Logs. A preset is a predefined set of XDR data fields that are relevant for a specific use case, such as process execution, file operations, or network activity. A preset can help you simplify and standardize your XQL queries by selecting the most important fields for your analysis. You can use presets with any Cortex data lake data source, but not with third-party data sources.Reference:

Datasets and Presets

XQL Language Reference

asked 23/09/2024
Tracy Nicholas
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first