Palo_Alto_Networks
XSIAM-ENGINEER · Question #9
XSIAM-ENGINEER Question #9: Real Exam Question with Answer & Explanation
Sign in or unlock XSIAM-ENGINEER to reveal the answer and full explanation for question #9. The question stem and answer options stay visible for context.
Question
An engineer is conducting a threat actor emulated test to determine which Cortex XDR module would provide protection or alert on a real-world attack. The first test was prevented. Which action must the engineer take to enable continued testing?
Options
- ARemove the hash from the restrictions profile.
- BAdd an indicator exclusion.
- CAdd a prevention rule.
- DChange the profile from "alert" to "prevent" for the BTP module.
Unlock XSIAM-ENGINEER to see the answer
You've previewed enough free XSIAM-ENGINEER questions. Unlock XSIAM-ENGINEER for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.