Cisco XDR Incident Manager provides a structured response workflow that organizes and guides analysts through suggested incident-response tasks. These tasks cover identification, containment, eradication, and recovery. Recovery includes confirming that malicious activity has been removed and restoring affected systems safely. Therefore, D is the only option that matches Incident Manager’s guided and prioritized response functionality. The feature does not merely calculate the average time required to identify an incident or predict how long resolution will take. Backup activities following a false-positive determination are also not its defining purpose. Incident Manager combines correlated incident evidence, investigation context, and recommended tasks so analysts can focus on the appropriate response actions and move the incident systematically toward containment and recovery. Cisco XDR security automation guidance
================
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit