Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Palo Alto Networks XDR-Analyst Exam - Topic 1 Question 16 Discussion

Which Exploit Protection Module (EPM) can be used to prevent attacks based on OS function?
B) JIT Mitigation
A) UASLR
C) Memory Limit Heap Spray Check
D) DLL Security

Palo Alto Networks XDR-Analyst Exam - Topic 1 Question 16 Discussion

Actual exam question for Palo Alto Networks's XDR-Analyst exam
Question #: 16
Topic #: 1
[All XDR-Analyst Questions]

Which Exploit Protection Module (EPM) can be used to prevent attacks based on OS function?

Show Suggested Answer Hide Answer
Suggested Answer: B

JIT Mitigation is an Exploit Protection Module (EPM) that can be used to prevent attacks based on OS function. JIT Mitigation protects against exploits that use the Just-In-Time (JIT) compiler of the OS to execute malicious code. JIT Mitigation monitors the memory pages that are allocated by the JIT compiler and blocks any attempts to execute code from those pages. This prevents attackers from using the JIT compiler as a way to bypass other security mechanisms such as Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR).Reference:

Palo Alto Networks. (2023). PCDRA Study Guide. PDF file. Retrieved from https://www.paloaltonetworks.com/content/dam/pan/en_US/assets/pdf/datasheets/education/pcdra-study-guide.pdf

Palo Alto Networks. (2021). Exploit Protection Modules. Web page. Retrieved from https://docs.paloaltonetworks.com/traps/6-0/traps-endpoint-security-manager-admin/traps-endpoint-security-policies/exploit-protection-modules.html


Contribute your Thoughts:

0/2000 characters
Jacob
3 days ago
Totally agree, UASLR is the best choice here!
upvoted 0 times
...
Maryann
8 days ago
Surprised UASLR is still the answer, thought it was outdated.
upvoted 0 times
...
Joanna
13 days ago
Memory Limit Heap Spray Check is underrated, but not for OS functions.
upvoted 0 times
...
Myra
19 days ago
I thought JIT Mitigation was the go-to for that!
upvoted 0 times
...
Lashawnda
24 days ago
It's definitely UASLR for OS function attacks.
upvoted 0 times
...
Avery
29 days ago
DLL Security sounds familiar, but I don’t think it directly prevents OS function attacks like the others might.
upvoted 0 times
...
Marjory
1 month ago
I feel like Memory Limit Heap Spray Check could be relevant, but I’m not confident it’s the best answer for this question.
upvoted 0 times
...
Bette
1 month ago
I remember practicing with a question about JIT Mitigation, but I can't recall if it specifically targets OS functions.
upvoted 0 times
...
Tracey
1 month ago
I think UASLR might be the right choice since it deals with address space layout randomization, but I'm not entirely sure.
upvoted 0 times
...

Save Cancel