Courseiva
Alert Lifecycle And Incident CorrelationmediumMultiple ChoiceObjective-mapped

XDR-Analyst Alert Lifecycle And Incident Correlation Practice Question

During the alert-to-incident lifecycle in Cortex XDR, an alert is generated by an endpoint agent, evaluated by analytics, and subsequently combined into an existing incident. What status does the newly added alert assume upon joining the incident?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The alert automatically adopts the status of the parent incident (e.g., Under Investigation or Resolved).

When new alerts are added to an existing incident via correlation, they inherit the lifecycle context of the parent incident while retaining their individual alert states.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The alert status changes permanently to 'False Positive'.

    Why it's wrong here

    Alerts only become false positives if explicitly triaged and marked as such by an analyst.

  • The alert is dropped from the database due to duplicate correlation.

    Why it's wrong here

    Correlated alerts are retained in the database for forensic depth and audit trails.

  • The alert automatically adopts the status of the parent incident (e.g., Under Investigation or Resolved).

    Why this is correct

    Correlated alerts join the incident structure and reflect the operational state of the parent incident.

  • The alert is placed in 'Quarantine' status pending manual review.

    Why it's wrong here

    Quarantine is an endpoint isolation action, not an alert status.

About these practice questions

One of 210 original XDR-Analyst practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This XDR-Analyst practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XDR-Analyst exam.