Skip to content
PANW-XDRA
Incident Handling and Response
medium
Question 1 of 68

A team is mapping a workflow to alert evidence. Which choice best supports the need to review evidence tied to an alert before choosing a response while validating an investigation path?

ACausality chain
BAlert evidence
CExceptions
DExclusions

Educational Content — CertQnA practice questions are written against official exam objectives, covering the same domains tested on the real exam. All content is original and independent — not actual exam questions, not affiliated with any certification vendor. Learn more about our content policy

Discussion

Be the first to share your understanding of this concept

⚠️ Discussion is for concept clarification only. Do not share or request actual exam questions or answers.

Sign in to join the discussion