XSIAM-ANALYST · Question #54
Which type of alert in Cortex XSIAM is primarily based on endpoint telemetry and behavior?
The correct answer is D. BIOC. BIOC (Behavioral Indicators of Compromise) alerts are specifically designed to detect suspicious endpoint behavior by analyzing telemetry collected by the XDR agent - things like unusual process chains, privilege escalation, or lateral movement patterns - making D the correct…
Question
Which type of alert in Cortex XSIAM is primarily based on endpoint telemetry and behavior?
Options
- AIOC
- BCorrelation
- CXDR Agent
- DBIOC
How the community answered
(30 responses)- A3% (1)
- C3% (1)
- D93% (28)
Explanation
BIOC (Behavioral Indicators of Compromise) alerts are specifically designed to detect suspicious endpoint behavior by analyzing telemetry collected by the XDR agent - things like unusual process chains, privilege escalation, or lateral movement patterns - making D the correct answer.
Why the others are wrong:
- A. IOC alerts match against known-bad signatures (hashes, IPs, domains), not behavioral patterns - they flag what is known, not what looks suspicious.
- B. Correlation alerts aggregate events across multiple data sources using rule logic, not specifically endpoint telemetry behavior.
- C. XDR Agent is the endpoint software that collects telemetry - it's a component, not an alert type.
Memory tip: Think BIOC = Behavior. If the alert is asking "what did this endpoint do?" - that's BIOC. If it's asking "did we see a known bad thing?" - that's IOC.
Topics
Community Discussion
No community discussion yet for this question.