XDR-ENGINEER · Question #43
A Custom Prevention rule that was determined to be a false positive alert needs to be tuned. The behavior was determined to be authorized and expected on the affected endpoint. Based on the image…
The correct answer is A. Apply an alert exception B. Apply an alert exclusion to the XDR behavioral indicator of compromise (BIOC) alert. When authorized behavior triggers a Custom Prevention rule's BIOC alert, the two targeted remediation options are to apply an alert exception (A) or apply an alert exclusion scoped to the BIOC alert type (B). Both actions suppress the false positive at the right layer - alert…
Question
A Custom Prevention rule that was determined to be a false positive alert needs to be tuned. The behavior was determined to be authorized and expected on the affected endpoint. Based on the image below, which two steps could be taken? (Choose two.) [Image description: A Custom Prevention rule configuration, assumed to trigger a Behavioral Indicator of Compromise (BIOC) alert for authorized behavior]
Options
- AApply an alert exception
- BApply an alert exclusion to the XDR behavioral indicator of compromise (BIOC) alert
- CApply an alert exclusion to the XDR agent alert
- DModify the behavioral indicator of compromise (BIOC) logic
How the community answered
(28 responses)- A75% (21)
- C14% (4)
- D11% (3)
Explanation
When authorized behavior triggers a Custom Prevention rule's BIOC alert, the two targeted remediation options are to apply an alert exception (A) or apply an alert exclusion scoped to the BIOC alert type (B). Both actions suppress the false positive at the right layer - alert exceptions let you carve out specific conditions (endpoint, process, user) from triggering an alert, while a BIOC alert exclusion tells the system to ignore that particular behavioral pattern for the matching BIOC category.
Why C is wrong: The alert in question is a BIOC alert, not an XDR agent alert (a distinct category covering threats like malware detected by the endpoint protection module). Applying an exclusion to the wrong alert type won't silence the Custom Prevention rule's output.
Why D is wrong: Modifying the underlying BIOC logic is too broad - it would change detection behavior system-wide, not just for the authorized endpoint. False positive tuning should be scoped narrowly; the BIOC logic itself is not what needs to change.
Memory tip: When tuning a Custom Prevention / BIOC false positive, ask "am I excepting or excluding the right alert type?" - match your suppression to the alert category (BIOC, not agent), and never reach for logic modification when a scoped exception will do.
Topics
Community Discussion
No community discussion yet for this question.