Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Palo Alto Networks XDR-Analyst Exam - Topic 4 Question 8 Discussion

Actual exam question for Palo Alto Networks's XDR-Analyst exam
Question #: 8
Topic #: 4
[All XDR-Analyst Questions]

Where can SHA256 hash values be used in Cortex XDR Malware Protection Profiles?

Show Suggested Answer Hide Answer
Suggested Answer: D

Cortex XDR Malware Protection Profiles allow you to configure the malware prevention settings for Windows, Linux, and macOS endpoints. You can use SHA256 hash values in the Windows Malware Protection Profile to indicate allowed executables that you want to exclude from malware scanning. This can help you reduce false positives and improve performance by skipping the scanning of known benign files. You can add up to 1000 SHA256 hash values per profile. You cannot use SHA256 hash values in the Linux or macOS Malware Protection Profiles, but you can use other criteria such as file path, file name, or signer to exclude files from scanning.Reference:

Malware Protection Profiles

Configure a Windows Malware Protection Profile

PCDRA Study Guide


Contribute your Thoughts:

0/2000 characters
Cornell
20 days ago
I think C is wrong, SHA256 is definitely used.
upvoted 0 times
...
Arlene
25 days ago
A and D are correct!
upvoted 0 times
...
Stephanie
2 months ago
I think option D sounds right, but I also have a vague memory of something related to Linux and Java libraries.
upvoted 0 times
...
Tasia
2 months ago
I feel like SHA256 hashes might not be applicable at all in Cortex XDR, but that seems too straightforward for an exam question.
upvoted 0 times
...
Mireya
2 months ago
I remember practicing a question about allowed signers in macOS, but I can't recall if it specifically mentioned SHA256.
upvoted 0 times
...
Mattie
2 months ago
I think SHA256 hashes are definitely used in the Windows Malware Protection Profile, but I'm not sure if it's for executables or something else.
upvoted 0 times
...

Save Cancel