What is the meaning of "ExpectedResult" in Panther Rules compared to Panther Policies?
QUESTION
What is the meaning of ExpectedResult
in Panther Rules compared to Panther Policies?
ANSWER
-
In Rules, the
ExpectedResult
(True
orFalse
) indicates whether the rule should trigger an alert based on the unit test data. - In Policies,
True
means that the resource is compliant, which is a positive outcome. WhileFalse
indicates that the resource is not compliant.