An XDR engineer is configuring an automation playbook to respond to high-severity malware alerts by
automatically isolating the affected endpoint and notifying the security team via email. The playbook should
only trigger for alerts generated by the Cortex XDR analytics engine, not custom BIOCs. Which two
conditions should the engineer include in the playbook trigger to meet these requirements? (Choose two.)
An XDR engineer is configuring an automation playbook to respond to high-severity malware alerts by
automatically isolating the affected endpoint and notifying the security team via email. The playbook should
only trigger for alerts generated by the Cortex XDR analytics engine, not custom BIOCs. Which two
conditions should the engineer include in the playbook trigger to meet these requirements? (Choose two.)