Paloalto Networks Palo Alto Networks XDR Engineer XDR-Engineer Question # 13 Topic 2 Discussion

Paloalto Networks Palo Alto Networks XDR Engineer XDR-Engineer Question # 13 Topic 2 Discussion

XDR-Engineer Exam Topic 2 Question 13 Discussion:
Question #: 13
Topic #: 2

An XDR engineer is configuring an automation playbook to respond to high-severity malware alerts by automatically isolating the affected endpoint and notifying the security team via email. The playbook should only trigger for alerts generated by the Cortex XDR analytics engine, not custom BIOCs. Which two conditions should the engineer include in the playbook trigger to meet these requirements? (Choose two.)


A.

Alert severity is High


B.

Alert source is Cortex XDR Analytics


C.

Alert category is Malware


D.

Alert status is New


Get Premium XDR-Engineer Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.