ExamGecko
Question list
Search
Search

Question 75 - PCDRA discussion

Report
Export

To stop a network-based attack, any interference with a portion of the attack pattern is enough to prevent it from succeeding. Which statement is correct regarding the Cortex XDR Analytics module?

A.
It does not interfere with any portion of the pattern on the endpoint.
Answers
A.
It does not interfere with any portion of the pattern on the endpoint.
B.
It interferes with the pattern as soon as it is observed by the firewall.
Answers
B.
It interferes with the pattern as soon as it is observed by the firewall.
C.
It does not need to interfere with the any portion of the pattern to prevent the attack.
Answers
C.
It does not need to interfere with the any portion of the pattern to prevent the attack.
D.
It interferes with the pattern as soon as it is observed on the endpoint.
Answers
D.
It interferes with the pattern as soon as it is observed on the endpoint.
Suggested answer: D

Explanation:

The correct statement regarding the Cortex XDR Analytics module is D, it interferes with the pattern as soon as it is observed on the endpoint. The Cortex XDR Analytics module is a feature of Cortex XDR that uses machine learning and behavioral analytics to detect and prevent network-based attacks on endpoints. The Cortex XDR Analytics module analyzes the network traffic and activity on the endpoint, and compares it with the attack patterns defined by Palo Alto Networks threat research team. The Cortex XDR Analytics module interferes with the attack pattern as soon as it is observed on the endpoint, by blocking the malicious network connection, process, or file. This way, the Cortex XDR Analytics module can stop the attack before it causes any damage or compromise.

The other statements are incorrect for the following reasons:

A is incorrect because the Cortex XDR Analytics module does interfere with the attack pattern on the endpoint, by blocking the malicious network connection, process, or file. The Cortex XDR Analytics module does not rely on the firewall or any other network device to stop the attack, but rather uses the Cortex XDR agent installed on the endpoint to perform the interference.

B is incorrect because the Cortex XDR Analytics module does not interfere with the attack pattern as soon as it is observed by the firewall. The Cortex XDR Analytics module does not depend on the firewall or any other network device to detect or prevent the attack, but rather uses the Cortex XDR agent installed on the endpoint to perform the analysis and interference. The firewall may not be able to observe or block the attack pattern if it is encrypted, obfuscated, or bypassed by the attacker.

C is incorrect because the Cortex XDR Analytics module does need to interfere with the attack pattern to prevent the attack. The Cortex XDR Analytics module does not only detect the attack pattern, but also prevents it from succeeding by blocking the malicious network connection, process, or file. The Cortex XDR Analytics module does not rely on any other response mechanism or human intervention to stop the attack, but rather uses the Cortex XDR agent installed on the endpoint to perform the interference.

Cortex XDR Analytics Module

Cortex XDR Analytics Module Detection and Prevention

asked 23/09/2024
Matias Cordero Ochoa
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first