nerdexam
Palo_Alto_Networks

XDR-ANALYST · Question #101

XDR-ANALYST Question #101: Real Exam Question with Answer & Explanation

The correct answer is B. Discovery. The type of BIOC rule that is currently available in Cortex XDR is Discovery. A Discovery BIOC rule is a rule that detects suspicious or malicious behavior on endpoints based on the Cortex XDR data. A Discovery BIOC rule can use various event types, such as file, injection, load

Question

Which type of BIOC rule is currently available in Cortex XDR?

Options

  • AThreat Actor
  • BDiscovery
  • CNetwork
  • DDropper

Explanation

The type of BIOC rule that is currently available in Cortex XDR is Discovery. A Discovery BIOC rule is a rule that detects suspicious or malicious behavior on endpoints based on the Cortex XDR data. A Discovery BIOC rule can use various event types, such as file, injection, load image, network, process, registry, or user, to define the criteria for the rule. A Discovery BIOC rule can also use operators, functions, and variables to create complex logic and conditions for the rule. A Discovery BIOC rule can generate alerts when the rule is triggered, and these alerts can be grouped into incidents for further investigation and response.

Community Discussion

No community discussion yet for this question.

Full XDR-ANALYST Practice