Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Palo Alto Networks SecOps-Pro Exam - Topic 3 Question 7 Discussion

A customer is investigating a security incident in which unusual network traffic is observed and a malicious process is identified on an endpoint. Which Cortex XDR capability assists with correlating firewall network logs and endpoint data in this environment?
A) Log stitching
B) User authentication management
C) Indicator of compromise (IOC) rule
D) Analytics

Palo Alto Networks SecOps-Pro Exam - Topic 3 Question 7 Discussion

Actual exam question for Palo Alto Networks's SecOps-Pro exam
Question #: 7
Topic #: 3
[All SecOps-Pro Questions]

A customer is investigating a security incident in which unusual network traffic is observed and a malicious process is identified on an endpoint. Which Cortex XDR capability assists with correlating firewall network logs and endpoint data in this environment?

Show Suggested Answer Hide Answer
Suggested Answer: A

In the Palo Alto Networks Cortex XDR ecosystem, Log Stitching is the fundamental technology that enables the 'X' (Extended) in XDR. It is the process of automatically reassembling fragmented data from disparate sources---such as Next-Generation Firewalls (NGFW), GlobalProtect, and the Cortex XDR agent---into a single, cohesive narrative.

How it Works: When a firewall identifies a network flow and an endpoint agent identifies a process execution, these are initially two separate logs. Cortex XDR uses 'stitching' to link these logs by matching common attributes (such as timestamps, source/destination IP addresses, and ports) to identify the Causality Group Owner (CGO).

The Result: This allows an analyst to see exactly which local process on the endpoint (e.g., powershell.exe) was responsible for generating the specific malicious network traffic caught by the firewall. Without log stitching, these would remain two isolated events, making it much harder to prove the 'cause and effect' of an attack.

Why other options are incorrect:

User authentication management: Focuses on identity and access, not the correlation of network and process telemetry.

Indicator of compromise (IOC) rule: These are typically used to flag known malicious artifacts (like a specific file hash or IP address) but do not perform the structural correlation of different log types.

Analytics: While Analytics uses the data provided by log stitching to identify behavioral anomalies, the specific capability that performs the correlation and 'linking' of the firewall and endpoint logs is the stitching process itself.


Contribute your Thoughts:

0/2000 characters
Novella
4 days ago
I’m leaning towards C) IOC rule, but not sure.
upvoted 0 times
...
Carin
9 days ago
Totally agree with A! It’s crucial for incident response.
upvoted 0 times
...
Von
14 days ago
Wait, is log stitching really that effective?
upvoted 0 times
...
Marshall
20 days ago
I thought it was D) Analytics, but I see the point.
upvoted 0 times
...
Nathalie
25 days ago
Definitely A) Log stitching! It connects the dots.
upvoted 0 times
...
Jesus
30 days ago
I’m confused; I thought IOC rules were more about identifying threats rather than correlating logs. Maybe it’s D) Analytics after all?
upvoted 0 times
...
Ozell
1 month ago
I feel like I've seen a question similar to this before, and it was about correlating data, which makes me lean towards A) Log stitching.
upvoted 0 times
...
Elvera
1 month ago
I'm not entirely sure, but I remember something about D) Analytics being used to analyze patterns in data.
upvoted 0 times
...
Hyman
2 months ago
I think the answer might be A) Log stitching, since it sounds like it would help combine logs from different sources.
upvoted 0 times
...

Save Cancel