Question: 1/50
A security team is designing an XSIAM deployment and wants the platform to automatically correlate alerts, endpoint activity, and network logs into a single incident view. Which XSIAM capability primarily provides this outcome?
Data retention policies for cold storage
Incident correlation and automation engine
Manual case creation in the incident queue
Role-based access control (RBAC) for analysts