ExamGecko
Question list
Search
Search

Question 34 - PCDRA discussion

Report
Export

What are two purposes of ''Respond to Malicious Causality Chains'' in a Cortex XDR Windows Malware profile? (Choose two.)

A.
Automatically close the connections involved in malicious traffic.
Answers
A.
Automatically close the connections involved in malicious traffic.
B.
Automatically kill the processes involved in malicious activity.
Answers
B.
Automatically kill the processes involved in malicious activity.
C.
Automatically terminate the threads involved in malicious activity.
Answers
C.
Automatically terminate the threads involved in malicious activity.
D.
Automatically block the IP addresses involved in malicious traffic.
Answers
D.
Automatically block the IP addresses involved in malicious traffic.
Suggested answer: B, D

Explanation:

The ''Respond to Malicious Causality Chains'' feature in a Cortex XDR Windows Malware profile allows the agent to take automatic actions against network connections and processes that are involved in malicious activity on the endpoint.The feature has two modes: Block IP Address and Kill Process1.

The two purposes of ''Respond to Malicious Causality Chains'' in a Cortex XDR Windows Malware profile are:

Automatically kill the processes involved in malicious activity. This can help to stop the malware from spreading or doing any further damage.

Automatically block the IP addresses involved in malicious traffic. This can help to prevent the malware from communicating with its command and control server or other malicious hosts.

The other two options, automatically close the connections involved in malicious traffic and automatically terminate the threads involved in malicious activity, are not specific to ''Respond to Malicious Causality Chains''. They are general security measures that the agent can perform regardless of the feature.

Cortex XDR Agent Security Profiles

Cortex XDR Agent 7.5 Release Notes

PCDRA: What are purposes of ''Respond to Malicious Causality Chains'' in ...

asked 23/09/2024
Verónica Crespo
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first