Palo_Alto_Networks
SECOPS-PRO · Question #38
An analyst investigating an incident using Cortex XSIAM confirms that the files involved are not malware, but wants to determine if the incident is a genuine threat or a false positive. Which action…
The correct answer is C. Viewing the information alerts for the incident. Viewing the information alerts for the incident provides insight into the threat nature and helps determine if it's a genuine threat or false positive.
Incident Triage and Investigation
Question
An analyst investigating an incident using Cortex XSIAM confirms that the files involved are not malware, but wants to determine if the incident is a genuine threat or a false positive. Which action will provide the analyst information for making the determination?
Options
- AChecking the endpoint details if the machines involved
- BViewing the timeline and filter for a alerts
- CViewing the information alerts for the incident
- DChecking the incident War Room for history and command tasks
How the community answered
(28 responses)- A7% (2)
- B14% (4)
- C75% (21)
- D4% (1)
Explanation
Viewing the information alerts for the incident provides insight into the threat nature and helps determine if it's a genuine threat or false positive.
Topics
#Cortex XSIAM#incident investigation#false positive analysis#information alerts
Community Discussion
No community discussion yet for this question.