ExamGecko
Question list
Search
Search

Question 79 - PCDRA discussion

Report
Export

Which type of IOC can you define in Cortex XDR?

A.
Destination IP Address
Answers
A.
Destination IP Address
B.
Source IP Address
Answers
B.
Source IP Address
C.
Source port
Answers
C.
Source port
D.
Destination IP Address: Destination
Answers
D.
Destination IP Address: Destination
Suggested answer: A

Explanation:

Cortex XDR allows you to define IOC rules based on various types of indicators of compromise (IOC) that you can use to detect and respond to threats in your network. One of the types of IOC that you can define in Cortex XDR isdestination IP address, which is the IP address of the remote host that a local endpoint is communicating with. You can use this type of IOC to identify malicious network activity, such as connections to command and control servers, phishing sites, or malware distribution hosts. You can also specify the direction of the network traffic (inbound or outbound) and the protocol (TCP or UDP) for the destination IP address IOC.Reference:

Cortex XDR documentation portal

Is there a possibility to create an IOC list to employ it in a query?

Cortex XDR Datasheet

asked 23/09/2024
Ken Mak
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first