nerdexam
Palo_Alto_Networks

SECOPS-PRO · Question #38

An analyst investigating an incident using Cortex XSIAM confirms that the files involved are not malware, but wants to determine if the incident is a genuine threat or a false positive. Which action…

The correct answer is C. Viewing the information alerts for the incident. Viewing the information alerts for the incident provides insight into the threat nature and helps determine if it's a genuine threat or false positive.

Incident Triage and Investigation

Question

An analyst investigating an incident using Cortex XSIAM confirms that the files involved are not malware, but wants to determine if the incident is a genuine threat or a false positive. Which action will provide the analyst information for making the determination?

Options

  • AChecking the endpoint details if the machines involved
  • BViewing the timeline and filter for a alerts
  • CViewing the information alerts for the incident
  • DChecking the incident War Room for history and command tasks

How the community answered

(28 responses)
  • A
    7% (2)
  • B
    14% (4)
  • C
    75% (21)
  • D
    4% (1)

Explanation

Viewing the information alerts for the incident provides insight into the threat nature and helps determine if it's a genuine threat or false positive.

Topics

#Cortex XSIAM#incident investigation#false positive analysis#information alerts

Community Discussion

No community discussion yet for this question.

Full SECOPS-PRO Practice