nerdexam
Palo_Alto_Networks

XDR-ENGINEER · Question #8

An analyst considers an alert with the category of lateral movement to be allowed and not needing to be checked in the future. Based on the image below, which action can an engineer take to address…

The correct answer is B. Create an alert exclusion rule by using the alert source and alert name. Option B is correct because an alert exclusion rule is purpose-built to prevent specific alerts from surfacing in the future - it operates at the alert level, using the alert source and alert name to match and suppress the exact alert the analyst has deemed benign. This cleanly…

Alert Triage and Incident Response

Question

An analyst considers an alert with the category of lateral movement to be allowed and not needing to be checked in the future. Based on the image below, which action can an engineer take to address the requirement?

Options

  • ACreate a behavioral indicator of compromise (BIOC) suppression rule for the parent process and
  • BCreate an alert exclusion rule by using the alert source and alert name
  • CCreate a disable injection and prevention rule for the parent process indicated in the alert
  • DCreate an exception rule for the parent process and the exact command indicated in the alert

How the community answered

(45 responses)
  • A
    4% (2)
  • B
    84% (38)
  • C
    2% (1)
  • D
    9% (4)

Explanation

Option B is correct because an alert exclusion rule is purpose-built to prevent specific alerts from surfacing in the future - it operates at the alert level, using the alert source and alert name to match and suppress the exact alert the analyst has deemed benign. This cleanly satisfies the requirement without touching underlying security policies.

Why the distractors are wrong:

  • A (BIOC suppression): BIOC rules suppress behavioral detections tied to specific processes, not named alerts - this is the wrong mechanism for silencing a categorized alert.
  • C (Disable injection/prevention rule): This disables an endpoint protection action, not an alert - it weakens security posture rather than managing alert visibility.
  • D (Exception rule for parent process + exact command): Exception rules govern Exploit Protection or prevention policies at the process level; they're not designed to exclude alerts, and tying to an exact command is unnecessarily restrictive.

Memory tip: Match the tool to the object - if you want to silence an alert, use an alert exclusion rule targeting alert properties (source + name). Rules named after processes, behaviors, or injections act on endpoint actions, not on the alert pipeline itself.

Topics

#alert exclusion#lateral movement#BIOC suppression#alert management

Community Discussion

No community discussion yet for this question.

Full XDR-ENGINEER Practice