A Cortex XSIAM analyst in a SOC is reviewing an incident involving a workstation showing signs of a potential breach. The incident includes an alert from Cortex XDR Analytics Alert source "Remote service command execution from an uncommon source." As part of the incident handling process, the analyst must apply response actions to contain the threat effectively.
Which initial Cortex XDR agent response action should be taken to reduce attacker mobility on the network?
The correct answer is A -- Isolate Endpoint.
The most effective initial response to contain a breach and reduce attacker mobility is to isolate the endpoint. This action ensures that the compromised machine can no longer communicate with the network or external systems, effectively cutting off lateral movement and exfiltration by attackers, while still allowing controlled response operations.
'Isolate Endpoint is the primary response action used to immediately contain a threat by severing all network communication, thus limiting attacker movement during active incidents.'
Document Reference: EDU-270c-10-lab-guide_02.docx (1).pdf
Page: Page 40 (Incident Handling/SOC section)
Hyun
3 days agoLou
9 days agoAbel
14 days agoBlythe
19 days agoMichal
24 days agoWava
29 days agoNathalie
2 months agoMira
2 months agoNickolas
2 months agoJettie
2 months agoVirgina
2 months agoRoselle
2 months agoLavonna
3 months agoBrock
3 months agoLorean
3 months agoDyan
3 months agoDulce
3 months agoDaniel
3 months agoTyisha
4 months agoMichel
4 months agoGertude
4 months agoKati
4 months agoJenelle
5 months agoGilma
5 months agoMinna
4 months ago