nerdexam
Palo_Alto_Networks

XDR-ANALYST · Question #85

What should you do to automatically convert leads into alerts after investigating a lead?

The correct answer is B. Create IOC rules based on the set of the collected attribute-value pairs over the affected entities. To automatically convert leads into alerts after investigating a lead, you should create IOC rules based on the set of the collected attribute-value pairs over the affected entities concluded during the lead hunting. IOC rules are used to detect known threats based on…

Threat Hunting and Investigation

Question

What should you do to automatically convert leads into alerts after investigating a lead?

Options

  • ALead threats can't be prevented in the future because they already exist in the environment.
  • BCreate IOC rules based on the set of the collected attribute-value pairs over the affected entities
  • CCreate BIOC rules based on the set of the collected attribute-value pairs over the affected entities
  • DBuild a search query using Query Builder or XQL using a list of lOCs.

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    79% (23)
  • C
    7% (2)
  • D
    10% (3)

Explanation

To automatically convert leads into alerts after investigating a lead, you should create IOC rules based on the set of the collected attribute-value pairs over the affected entities concluded during the lead hunting. IOC rules are used to detect known threats based on indicators of compromise (IOCs) such as file hashes, IP addresses, domain names, etc. By creating IOC rules from the leads, you can prevent future occurrences of the same threats and generate alerts for them.

Topics

#IOC rules#lead investigation#alert creation#threat hunting

Community Discussion

No community discussion yet for this question.

Full XDR-ANALYST Practice