Palo_Alto_Networks
SECOPS-PRO · Question #54
Which action should an administrator take to create automated response actions when a user account is compromised, allowing attacker to upload data to an external IP address and infect a machine on…
The correct answer is C. Create playbook triggers in Cortex XSIAM and run playbooks for each alert. Creating playbook triggers in Cortex XSIAM allows automated execution of playbooks in response to alerts for specific scenarios, such as a compromised user account.
Security Operations Automation
Question
Which action should an administrator take to create automated response actions when a user account is compromised, allowing attacker to upload data to an external IP address and infect a machine on the company network with malware?
Options
- ACreate automation rules in Cortex XDR that will trigger for each alert.
- BCreate a script in Cortex XSOAR that will run a playbook based on the scenario.
- CCreate playbook triggers in Cortex XSIAM and run playbooks for each alert.
- DMap the events as type of Cortex XSOAR incident, then run a playbook.
How the community answered
(38 responses)- A5% (2)
- B3% (1)
- C82% (31)
- D11% (4)
Explanation
Creating playbook triggers in Cortex XSIAM allows automated execution of playbooks in response to alerts for specific scenarios, such as a compromised user account.
Topics
#Cortex XSIAM#playbook automation#automated response#incident orchestration
Community Discussion
No community discussion yet for this question.