Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Palo Alto Networks Exam XDR-Engineer Topic 3 Question 3 Discussion

Actual exam question for Palo Alto Networks's XDR-Engineer exam
Question #: 3
Topic #: 3
[All XDR-Engineer Questions]

[Detection Engineering]

A Custom Prevention rule that was determined to be a false positive alert needs to be tuned. The behavior was determined to be authorized and expected on the affected endpoint. Based on the image below, which two steps could be taken? (Choose two.)

[Image description: A Custom Prevention rule configuration, assumed to trigger a Behavioral Indicator of Compromise (BIOC) alert for authorized behavior]

Show Suggested Answer Hide Answer
Suggested Answer: A, B

Contribute your Thoughts:

Currently there are no comments in this discussion, be the first to comment!


Save Cancel