What is a difference between cold storage and hot storage in Cortex?
A.
Cold storage is required, while hot storage is optional.
B.
Cold storage and hot storage can be stored in different cloud locations.
C.
Logs in cold storage have more details than logs stored in hot storage.
D.
Querying logs in cold storage takes more time than querying logs in hot storage.
The Answer Is:
D
This question includes an explanation.
Explanation:
In the Cortex Data Lake (utilized by XDR and XSIAM), storage is tiered to balance performance and cost-efficiency.
Hot Storage: This is the high-performance tier where data is immediately available for searching and analysis. Queries run against hot storage are near-instantaneous. Typically, organizations keep the most recent 30 to 90 days of data in hot storage for active investigation.
Cold Storage: This is a cost-effective tier for long-term retention (compliance). Data in cold storage is compressed and archived. To query this data, it must first be "re-hydrated" or restored to a searchable state, which inherently takes more time than querying active logs in hot storage.
Correction: I have clarified that while both storage types contain the same log data, the access latency is the primary differentiator.
SecOps-Pro PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 65% Discount on All Products,
Use Coupon: "ac4s65"