List of questions
Related questions
Question 71 - PCDRA discussion
While working the alerts involved in a Cortex XDR incident, an analyst has found that every alert in this incident requires an exclusion. What will the Cortex XDR console automatically do to this incident if all alerts contained have exclusions?
A.
mark the incident as Unresolved
B.
create a BIOC rule excluding this behavior
C.
create an exception to prevent future false positives
D.
mark the incident as Resolved -- False Positive
Your answer:
0 comments
Sorted by
Leave a comment first