ExamGecko
Question list
Search
Search

Question 52 - PCDRA discussion

Report
Export

How does Cortex XDR agent for Windows prevent ransomware attacks from compromising the file system?

A.
by encrypting the disk first.
Answers
A.
by encrypting the disk first.
B.
by utilizing decoy Files.
Answers
B.
by utilizing decoy Files.
C.
by retrieving the encryption key.
Answers
C.
by retrieving the encryption key.
D.
by patching vulnerable applications.
Answers
D.
by patching vulnerable applications.
Suggested answer: B

Explanation:

Cortex XDR agent for Windows prevents ransomware attacks from compromising the file system by utilizing decoy files. Decoy files are randomly generated files that are placed in strategic locations on the endpoint, such as the user's desktop, documents, and pictures folders. These files are designed to look like valuable data that ransomware would target for encryption. When Cortex XDR agent detects that a process is attempting to access or modify a decoy file, it immediately blocks the process and alerts the administrator. This way, Cortex XDR agent can stop ransomware attacks before they can cause any damage to the real files on the endpoint.Reference:

Anti-Ransomware Protection

PCDRA Study Guide

asked 23/09/2024
stefano atzei
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first