nerdexam
Palo_Alto_Networks

XSIAM-ANALYST · Question #39

You observe that a CVE is impacting multiple assets. How can you use ASM to investigate further? (Choose two)

The correct answer is A. Review asset tags and status C. Validate attack surface rule hits. A (Review asset tags and status) is correct because ASM lets you filter and prioritize affected assets using tags (e.g., environment, owner, criticality) and status fields, giving you immediate context on which assets are exposed and how severe the risk is across your…

Attack Surface Management

Question

You observe that a CVE is impacting multiple assets. How can you use ASM to investigate further? (Choose two)

Options

  • AReview asset tags and status
  • BTrigger a Cortex data purge
  • CValidate attack surface rule hits
  • DDisable detection rules

How the community answered

(15 responses)
  • A
    73% (11)
  • B
    7% (1)
  • D
    20% (3)

Explanation

A (Review asset tags and status) is correct because ASM lets you filter and prioritize affected assets using tags (e.g., environment, owner, criticality) and status fields, giving you immediate context on which assets are exposed and how severe the risk is across your inventory.

C (Validate attack surface rule hits) is correct because ASM uses rules to detect exposure patterns - confirming which rules triggered against the CVE tells you exactly which assets match the vulnerable condition, helping you scope and prioritize remediation.

B (Trigger a Cortex data purge) is wrong because purging data destroys investigative evidence and has no role in CVE analysis - it's a data management action, not a security investigation step.

D (Disable detection rules) is wrong because turning off rules would blind you to future hits of the same CVE and reduce your visibility, the opposite of what investigation requires.

Memory tip: Think of ASM investigation as "Tag it, then Validate it" - A tells you what is affected (asset context), C tells you why it was flagged (rule logic). Both expand your understanding; the distractors (purge and disable) shrink it.

Topics

#ASM#CVE Investigation#Asset Tags#Attack Surface Rules

Community Discussion

No community discussion yet for this question.

Full XSIAM-ANALYST Practice