Palo Alto Networks Certified Detection and Remediation Analyst (PCDRA) — Question 18

When creating a BIOC rule, which XQL query can be used?

Answer options

Correct answer: B

Explanation

Option B is correct because it includes both the event type and event sub-type, which are necessary to accurately identify the relevant process start events for the BIOC rule. The other options are incomplete or improperly structured, either lacking essential filters or having syntax errors, which would prevent them from functioning correctly.