A Cortex XSIAM analyst in a SOC is reviewing an incident involving a workstation showing signs of a potential breach. The incident includes an alert from Cortex XDR Analytics Alert source "Remote service command execution from an uncommon source." As part of the incident handling process, the analyst must apply response actions to contain the threat effectively.
Which initial Cortex XDR agent response action should be taken to reduce attacker mobility on the network?
The correct answer is A -- Isolate Endpoint.
The most effective initial response to contain a breach and reduce attacker mobility is to isolate the endpoint. This action ensures that the compromised machine can no longer communicate with the network or external systems, effectively cutting off lateral movement and exfiltration by attackers, while still allowing controlled response operations.
'Isolate Endpoint is the primary response action used to immediately contain a threat by severing all network communication, thus limiting attacker movement during active incidents.'
Document Reference: EDU-270c-10-lab-guide_02.docx (1).pdf
Page: Page 40 (Incident Handling/SOC section)
Nathalie
1 day agoMira
6 days agoNickolas
12 days agoJettie
17 days agoVirgina
22 days agoRoselle
27 days agoLavonna
1 month agoBrock
1 month agoLorean
1 month agoDyan
2 months agoDulce
2 months agoDaniel
2 months agoTyisha
2 months agoMichel
2 months agoGertude
2 months agoKati
3 months agoJenelle
3 months agoGilma
3 months agoMinna
3 months ago