MultipleChoice
[Cortex XDR Agent Configuration]
Based on the Malware profile image below, what happens when a new custom-developed application attempts to execute on an endpoint?

MultipleChoice
[Detection Engineering]
A Custom Prevention rule that was determined to be a false positive alert needs to be tuned. The behavior was determined to be authorized and expected on the affected endpoint. Based on the image below, which two steps could be taken? (Choose two.)
[Image description: A Custom Prevention rule configuration, assumed to trigger a Behavioral Indicator of Compromise (BIOC) alert for authorized behavior]
Options