nerdexam
Palo_Alto_Networks

XDR-ANALYST · Question #10

Which of the following represents the correct relation of alerts to incidents?

The correct answer is C. Alerts with same causality chains that occur within a given time frame are grouped together into an. The correct relation of alerts to incidents is that alerts with same causality chains that occur within a given time frame are grouped together into an incident. A causality chain is a sequence of events that are related to the same malicious activity, such as a malware…

Advanced Topics

Question

Which of the following represents the correct relation of alerts to incidents?

Options

  • AOnly alerts with the same host are grouped together into one Incident in a given time frame.
  • BAlerts that occur within a three-hour time frame are grouped together into one Incident.
  • CAlerts with same causality chains that occur within a given time frame are grouped together into an
  • DEvery alert creates a new Incident.

How the community answered

(19 responses)
  • A
    5% (1)
  • B
    11% (2)
  • C
    79% (15)
  • D
    5% (1)

Explanation

The correct relation of alerts to incidents is that alerts with same causality chains that occur within a given time frame are grouped together into an incident. A causality chain is a sequence of events that are related to the same malicious activity, such as a malware infection, a lateral movement, or a data exfiltration. Cortex XDR uses a set of rules that take into account different attributes of the alerts, such as the alert source, type, and time period, to determine if they belong to the same causality chain. By grouping related alerts into incidents, Cortex XDR reduces the number of individual events to review and provides a complete picture of the attack with rich investigative details.

Topics

#alerts#incidents#causality chain#incident grouping

Community Discussion

No community discussion yet for this question.

Full XDR-ANALYST Practice