ExamGecko
Question list
Search
Search

Question 70 - PCDRA discussion

Report
Export

Which of the following protection modules is checked first in the Cortex XDR Windows agent malware protection flow?

A.
Hash Verdict Determination
Answers
A.
Hash Verdict Determination
B.
Behavioral Threat Protection
Answers
B.
Behavioral Threat Protection
C.
Restriction Policy
Answers
C.
Restriction Policy
D.
Child Process Protection
Answers
D.
Child Process Protection
Suggested answer: A

Explanation:

The first protection module that is checked in the Cortex XDR Windows agent malware protection flow is the Hash Verdict Determination. This module compares the hash of the executable file that is about to run on the endpoint with a list of known malicious hashes stored in the Cortex XDR cloud. If the hash matches a malicious hash, the agent blocks the execution and generates an alert.If the hash does not match a malicious hash, the agent proceeds to the next protection module, which is the Restriction Policy1.

The Hash Verdict Determination module is the first line of defense against malware, as it can quickly and efficiently prevent known threats from running on the endpoint. However, this module cannot protect against unknown or zero-day threats, which have no known hash signature.Therefore, the Cortex XDR agent relies on other protection modules, such as Behavioral Threat Protection, Child Process Protection, and Exploit Protection, to detect and block malicious behaviors and exploits that may occur during the execution of the file1.

Palo Alto Networks Cortex XDR Documentation, File Analysis and Protection Flow

asked 23/09/2024
Tony Minjarez
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first