ExamGecko
Question list
Search
Search

Question 80 - PCDRA discussion

Report
Export

Under which conditions is Local Analysis evoked to evaluate a file before the file is allowed to run?

A.
The endpoint is disconnected or the verdict from WildFire is of a type benign.
Answers
A.
The endpoint is disconnected or the verdict from WildFire is of a type benign.
B.
The endpoint is disconnected or the verdict from WildFire is of a type unknown.
Answers
B.
The endpoint is disconnected or the verdict from WildFire is of a type unknown.
C.
The endpoint is disconnected or the verdict from WildFire is of a type malware.
Answers
C.
The endpoint is disconnected or the verdict from WildFire is of a type malware.
D.
The endpoint is disconnected or the verdict from WildFire is of a type grayware.
Answers
D.
The endpoint is disconnected or the verdict from WildFire is of a type grayware.
Suggested answer: B

Explanation:

Local Analysis is a feature of Cortex XDR that allows the agent to evaluate files locally on the endpoint, without sending them to WildFire for analysis. Local Analysis is evoked when the following conditions are met:

The endpoint isdisconnectedfrom the internet or the Cortex XDR management console, and therefore cannot communicate with WildFire.

The verdict from WildFire is of a typeunknown, meaning that WildFire has not yet analyzed the file or has not reached a conclusive verdict.

Local Analysis uses machine learning models to assess the behavior and characteristics of the file and assign it a verdict of either benign, malware, or grayware. If the verdict is malware or grayware, the agent will block the file from running and report it to the Cortex XDR management console. If the verdict is benign, the agent will allow the file to run and report it to the Cortex XDR management console.Reference:

Local Analysis

WildFire File Verdicts

asked 23/09/2024
Ibrahim SACCA
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first