ExamGecko
Question list
Search
Search

Question 20 - PCDRA discussion

Report
Export

Where would you go to add an exception to exclude a specific file hash from examination by the Malware profile for a Windows endpoint?

A.
Find the Malware profile attached to the endpoint, Under Portable Executable and DLL Examination add the hash to the allow list.
Answers
A.
Find the Malware profile attached to the endpoint, Under Portable Executable and DLL Examination add the hash to the allow list.
B.
From the rules menu select new exception, fill out the criteria, choose the scope to apply it to, hit save.
Answers
B.
From the rules menu select new exception, fill out the criteria, choose the scope to apply it to, hit save.
C.
Find the exceptions profile attached to the endpoint, under process exceptions select local analysis, paste the hash and save.
Answers
C.
Find the exceptions profile attached to the endpoint, under process exceptions select local analysis, paste the hash and save.
D.
In the Action Center, choose Allow list, select new action, select add to allow list, add your hash to the list, and apply it.
Answers
D.
In the Action Center, choose Allow list, select new action, select add to allow list, add your hash to the list, and apply it.
Suggested answer: D

Explanation:

To add an exception to exclude a specific file hash from examination by the Malware profile for a Windows endpoint, you need to use the Action Center in Cortex XDR. The Action Center allows you to create and manage actions that apply to endpoints, such as adding files or processes to the allow list or block list, isolating or unisolating endpoints, or initiating live terminal sessions. To add a file hash to the allow list, you need to choose Allow list, select new action, select add to allow list, add your hash to the list, and apply it.This will prevent the Malware profile from scanning or blocking the file on the endpoints that match the scope of the action.Reference: Cortex XDR 3: Responding to Attacks1, Action Center2

asked 23/09/2024
J.J. van Ingen
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first