nerdexam
Palo_Alto_Networks

XSIAM-ENGINEER · Question #9

An engineer is conducting a threat actor emulated test to determine which Cortex XDR module would provide protection or alert on a real-world attack. The first test was prevented. Which action must…

The correct answer is B. Add an indicator exclusion. To allow continued testing after the first emulated attack was blocked, the engineer must add an indicator exclusion. This bypasses enforcement for the specific test artifact, enabling repeated execution of the scenario to validate which Cortex XDR module detects or prevents…

Threat Prevention and Response

Question

An engineer is conducting a threat actor emulated test to determine which Cortex XDR module would provide protection or alert on a real-world attack. The first test was prevented. Which action must the engineer take to enable continued testing?

Options

  • ARemove the hash from the restrictions profile.
  • BAdd an indicator exclusion.
  • CAdd a prevention rule.
  • DChange the profile from "alert" to "prevent" for the BTP module.

How the community answered

(56 responses)
  • A
    4% (2)
  • B
    80% (45)
  • C
    11% (6)
  • D
    5% (3)

Explanation

To allow continued testing after the first emulated attack was blocked, the engineer must add an indicator exclusion. This bypasses enforcement for the specific test artifact, enabling repeated execution of the scenario to validate which Cortex XDR module detects or prevents the activity.

Topics

#indicator exclusion#threat emulation#BTP module#prevention bypass

Community Discussion

No community discussion yet for this question.

Full XSIAM-ENGINEER Practice