Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Palo Alto Networks XDR-Analyst Exam - Topic 2 Question 13 Discussion

What are two purposes of ''Respond to Malicious Causality Chains'' in a Cortex XDR Windows Malware profile? (Choose two.)
B) Automatically kill the processes involved in malicious activity. and D) Automatically block the IP addresses involved in malicious traffic.
A) Automatically close the connections involved in malicious traffic.
C) Automatically terminate the threads involved in malicious activity.

Palo Alto Networks XDR-Analyst Exam - Topic 2 Question 13 Discussion

Actual exam question for Palo Alto Networks's XDR-Analyst exam
Question #: 13
Topic #: 2
[All XDR-Analyst Questions]

What are two purposes of ''Respond to Malicious Causality Chains'' in a Cortex XDR Windows Malware profile? (Choose two.)

Show Suggested Answer Hide Answer
Suggested Answer: B, D

The ''Respond to Malicious Causality Chains'' feature in a Cortex XDR Windows Malware profile allows the agent to take automatic actions against network connections and processes that are involved in malicious activity on the endpoint.The feature has two modes: Block IP Address and Kill Process1.

The two purposes of ''Respond to Malicious Causality Chains'' in a Cortex XDR Windows Malware profile are:

Automatically kill the processes involved in malicious activity. This can help to stop the malware from spreading or doing any further damage.

Automatically block the IP addresses involved in malicious traffic. This can help to prevent the malware from communicating with its command and control server or other malicious hosts.

The other two options, automatically close the connections involved in malicious traffic and automatically terminate the threads involved in malicious activity, are not specific to ''Respond to Malicious Causality Chains''. They are general security measures that the agent can perform regardless of the feature.


Cortex XDR Agent Security Profiles

Cortex XDR Agent 7.5 Release Notes

PCDRA: What are purposes of ''Respond to Malicious Causality Chains'' in ...

Contribute your Thoughts:

0/2000 characters
Fletcher
6 days ago
I agree with A and C. Terminating threads can stop malware from spreading.
upvoted 0 times
...
Patrick
11 days ago
I feel like D is important too. Blocking IPs can prevent further attacks.
upvoted 0 times
...
Therese
16 days ago
I think A and B are the best choices. Closing connections and killing processes is crucial.
upvoted 0 times
...
Lera
21 days ago
I’m not sure about C), isn’t that a bit too specific?
upvoted 0 times
...
Ivette
26 days ago
Totally agree with A) and B)! Super useful features.
upvoted 0 times
...
Jacqueline
1 month ago
Wait, can it really close connections automatically? Sounds too good to be true!
upvoted 0 times
...
Regenia
1 month ago
I think D) should be one of them too.
upvoted 0 times
...
Jennifer
1 month ago
A) and B) are definitely the right choices!
upvoted 0 times
...
Pa
2 months ago
I’m a bit confused; I thought terminating threads was part of the process management, but I can't remember if it’s specifically mentioned in the context of Cortex XDR.
upvoted 0 times
...
Yolando
2 months ago
I feel like automatically closing connections could be a purpose too, but I can't recall if that's the same as blocking IPs.
upvoted 0 times
...
Robt
2 months ago
I remember practicing a similar question, and I think blocking IP addresses is definitely one of the options.
upvoted 0 times
...
Micah
2 months ago
I think one of the purposes might be to automatically kill the processes involved in malicious activity, but I'm not entirely sure about the second one.
upvoted 0 times
...

Save Cancel