Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Palo Alto Networks SecOps-Pro Exam - Topic 2 Question 9 Discussion

Which response action in Cortex XSIAM would be unavailable to a SOC analyst investigating an incident involving a Linux server?
A) File search and destroy
B) Live Terminal session initiation
C) Running a script
D) Halting network access

Palo Alto Networks SecOps-Pro Exam - Topic 2 Question 9 Discussion

Actual exam question for Palo Alto Networks's SecOps-Pro exam
Question #: 9
Topic #: 2
[All SecOps-Pro Questions]

Which response action in Cortex XSIAM would be unavailable to a SOC analyst investigating an incident involving a Linux server?

Show Suggested Answer Hide Answer
Suggested Answer: A

Cortex XSIAM (and XDR) agents provide a wide array of response actions, but these capabilities vary based on the operating system of the endpoint.

File Search and Destroy: This specific automated management action---which allows an administrator to search for a file across multiple endpoints and delete it in one click---is currently supported for Windows and macOS endpoints. It is not a native automated response action for Linux in the same 'Search and Destroy' menu context.

Supported Linux Actions: * Live Terminal (B): Analysts can initiate a remote SSH-like session to Linux endpoints for manual investigation.

Running a Script (C): Analysts can execute Python scripts on Linux endpoints to gather data or perform custom remediation.

Halting Network Access (D): Also known as Endpoint Isolation, this allows the analyst to cut off all network traffic to the Linux server except for the connection to the Cortex console.


Contribute your Thoughts:

0/2000 characters

Currently there are no comments in this discussion, be the first to comment!


Save Cancel