nerdexam
Palo_Alto_Networks

XDR-ANALYST · Question #6

What is the outcome of creating and implementing an alert exclusion?

The correct answer is B. The Cortex XDR console will hide those alerts. The outcome of creating and implementing an alert exclusion is that the Cortex XDR console will hide those alerts that match the exclusion criteria. An alert exclusion is a policy that allows you to filter out alerts that are not relevant, false positives, or low priority, and…

Configuration

Question

What is the outcome of creating and implementing an alert exclusion?

Options

  • AThe Cortex XDR agent will allow the process that was blocked to run on the endpoint.
  • BThe Cortex XDR console will hide those alerts.
  • CThe Cortex XDR agent will not create an alert for this event in the future.
  • DThe Cortex XDR console will delete those alerts and block ingestion of them in the future.

How the community answered

(44 responses)
  • A
    16% (7)
  • B
    70% (31)
  • C
    9% (4)
  • D
    5% (2)

Explanation

The outcome of creating and implementing an alert exclusion is that the Cortex XDR console will hide those alerts that match the exclusion criteria. An alert exclusion is a policy that allows you to filter out alerts that are not relevant, false positives, or low priority, and focus on the alerts that require your attention. When you create an alert exclusion, you can specify the criteria that define which alerts you want to exclude, such as alert name, severity, source, or endpoint. After you create an alert exclusion, Cortex XDR will hide any future alerts that match the criteria, and exclude them from incidents and search query results. However, the alert exclusion does not affect the behavior of the Cortex XDR agent or the security policy on the endpoint. The Cortex XDR agent will still create an alert for the event and apply the appropriate action, such as blocking or quarantining, according to the security policy. The alert exclusion only affects the visibility of the alert on the Cortex XDR console, not the actual protection of the endpoint.

Topics

#alert exclusion#console alerts#incident management#alert filtering

Community Discussion

No community discussion yet for this question.

Full XDR-ANALYST Practice