nerdexam
Palo_Alto_Networks

XSIAM-ANALYST · Question #54

Which type of alert in Cortex XSIAM is primarily based on endpoint telemetry and behavior?

The correct answer is D. BIOC. BIOC (Behavioral Indicators of Compromise) alerts are specifically designed to detect suspicious endpoint behavior by analyzing telemetry collected by the XDR agent - things like unusual process chains, privilege escalation, or lateral movement patterns - making D the correct…

Alert Triage and Investigation

Question

Which type of alert in Cortex XSIAM is primarily based on endpoint telemetry and behavior?

Options

  • AIOC
  • BCorrelation
  • CXDR Agent
  • DBIOC

How the community answered

(30 responses)
  • A
    3% (1)
  • C
    3% (1)
  • D
    93% (28)

Explanation

BIOC (Behavioral Indicators of Compromise) alerts are specifically designed to detect suspicious endpoint behavior by analyzing telemetry collected by the XDR agent - things like unusual process chains, privilege escalation, or lateral movement patterns - making D the correct answer.

Why the others are wrong:

  • A. IOC alerts match against known-bad signatures (hashes, IPs, domains), not behavioral patterns - they flag what is known, not what looks suspicious.
  • B. Correlation alerts aggregate events across multiple data sources using rule logic, not specifically endpoint telemetry behavior.
  • C. XDR Agent is the endpoint software that collects telemetry - it's a component, not an alert type.

Memory tip: Think BIOC = Behavior. If the alert is asking "what did this endpoint do?" - that's BIOC. If it's asking "did we see a known bad thing?" - that's IOC.

Topics

#BIOC#alert types#endpoint telemetry#behavioral detection

Community Discussion

No community discussion yet for this question.

Full XSIAM-ANALYST Practice