Palo_Alto_Networks
PSE-CORTEX · Question #52
A Cortex XSOAR customer wants to ingest from a single mailbox. The mailbox brings in reported phishing emails and email requests from human resources (HR) to onboard new users. The customer wants to…
The correct answer is C. Use an incident classifier based on field in each type of email to classify those containing "Phish. See the full explanation below for the reasoning.
Question
A Cortex XSOAR customer wants to ingest from a single mailbox. The mailbox brings in reported phishing emails and email requests from human resources (HR) to onboard new users. The customer wants to run two separate workflows from this mailbox, one for phishing and one for onboarding. What will allow Cortex XSOAR to accomplish this in the most efficient way?
Options
- AUsee machine learning (ML) to determine incident type
- BCreate two instances of the email integration and classily one instance as ingesting incidents of
- CUse an incident classifier based on field in each type of email to classify those containing "Phish
- DCreate a playbook to process and determine incident type based on content of the email
How the community answered
(27 responses)- A15% (4)
- B7% (2)
- C74% (20)
- D4% (1)
Community Discussion
No community discussion yet for this question.