nerdexam
Palo_Alto_Networks

XSIAM-ANALYST · Question #47

A SOC team member implements an incident starring configuration, but incidents created before this configuration were not starred. What is the cause of this behavior?

The correct answer is B. Starring configuration is applied to the newly created alerts, and the incident is subsequently. Incident starring rules work prospectively - only alerts generated after the configuration are starred, and then their incidents inherit the star. Existing incidents aren't retroactively updated.

Incident Management

Question

A SOC team member implements an incident starring configuration, but incidents created before this configuration were not starred. What is the cause of this behavior?

Options

  • AThe analyst must manually star incidents after determining which alerts within the incident were
  • BStarring configuration is applied to the newly created alerts, and the incident is subsequently
  • CIt takes 48 hours for the configuration to take effect.
  • DStarring is applied to alerts after they have been merged into incidents, but incidents are not

How the community answered

(35 responses)
  • A
    6% (2)
  • B
    91% (32)
  • C
    3% (1)

Explanation

Incident starring rules work prospectively - only alerts generated after the configuration are starred, and then their incidents inherit the star. Existing incidents aren't retroactively updated.

Topics

#incident starring#alert configuration#incident creation#SOC workflow

Community Discussion

No community discussion yet for this question.

Full XSIAM-ANALYST Practice