nerdexam
Palo_Alto_Networks

XSIAM-ANALYST · Question #9

In addition to defining the Rule Name and Severity Level, which step or set of steps accurately reflects how an analyst should configure an indicator prevention rule before reviewing and saving it?

The correct answer is C. Select profiles for prevention. An indicator prevention rule must bind supported indicator types (file hashes, IPs, domains) to specific prevention profiles so the agent can enforce blocking; after naming and setting severity, you choose the profiles and then pick those indicators before saving.

Threat Intelligence Management

Question

In addition to defining the Rule Name and Severity Level, which step or set of steps accurately reflects how an analyst should configure an indicator prevention rule before reviewing and saving it?

Options

  • AFilter and select file, IP address, and domain indicators.
  • BFilter and select indicators of any type.
  • CSelect profiles for prevention.
  • DSelect profiles for prevention.

How the community answered

(55 responses)
  • A
    2% (1)
  • B
    4% (2)
  • C
    85% (47)
  • D
    9% (5)

Explanation

An indicator prevention rule must bind supported indicator types (file hashes, IPs, domains) to specific prevention profiles so the agent can enforce blocking; after naming and setting severity, you choose the profiles and then pick those indicators before saving.

Topics

#indicator prevention rules#prevention profiles#rule configuration#IOC management

Community Discussion

No community discussion yet for this question.

Full XSIAM-ANALYST Practice