Paloalto Networks Palo Alto Networks XDR Engineer XDR-Engineer Question # 10 Topic 2 Discussion

Paloalto Networks Palo Alto Networks XDR Engineer XDR-Engineer Question # 10 Topic 2 Discussion

XDR-Engineer Exam Topic 2 Question 10 Discussion:
Question #: 10
Topic #: 2

An XDR engineer is creating a correlation rule to monitor login activity on specific systems. When the activity is identified, an alert is created. The alerts are being generated properly but are missing the username when viewed. How can the username information be included in the alerts?


A.

Select “Initial Access” in the MITRE ATT&CK mapping to include the username


B.

Update the query in the correlation rule to include the username field


C.

Add a mapping for the username field in the alert fields mapping


D.

Add a drill-down query to the alert which pulls the username field


Get Premium XDR-Engineer Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.