ExamGecko
Question list
Search
Search

Question 78 - PCDRA discussion

Report
Export

What should you do to automatically convert leads into alerts after investigating a lead?

A.
Lead threats can't be prevented in the future because they already exist in the environment.
Answers
A.
Lead threats can't be prevented in the future because they already exist in the environment.
B.
Create IOC rules based on the set of the collected attribute-value pairs over the affected entities concluded during the lead hunting.
Answers
B.
Create IOC rules based on the set of the collected attribute-value pairs over the affected entities concluded during the lead hunting.
C.
Create BIOC rules based on the set of the collected attribute-value pairs over the affected entities concluded during the lead hunting.
Answers
C.
Create BIOC rules based on the set of the collected attribute-value pairs over the affected entities concluded during the lead hunting.
D.
Build a search query using Query Builder or XQL using a list of lOCs.
Answers
D.
Build a search query using Query Builder or XQL using a list of lOCs.
Suggested answer: B

Explanation:

To automatically convert leads into alerts after investigating a lead, you should create IOC rules based on the set of the collected attribute-value pairs over the affected entities concluded during the lead hunting. IOC rules are used to detect known threats based on indicators of compromise (IOCs) such as file hashes, IP addresses, domain names, etc. By creating IOC rules from the leads, you can prevent future occurrences of the same threats and generate alerts for them.Reference:

PCDRA Study Guide, page 25

Cortex XDR 3: Handling Cortex XDR Alerts, section 3.2

Cortex XDR Documentation, section ''Create IOC Rules''

asked 23/09/2024
Hamza BOULHEND
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first