exam questions

Exam PCDRA All Questions

View all questions & answers for the PCDRA exam

Exam PCDRA topic 1 question 22 discussion

Actual exam question from Palo Alto Networks's PCDRA
Question #: 22
Topic #: 1
[All PCDRA Questions]

How does Cortex XDR agent for Windows prevent ransomware attacks from compromising the file system?

  • A. by encrypting the disk first.
  • B. by utilizing decoy Files.
  • C. by retrieving the encryption key.
  • D. by patching vulnerable applications.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
danups
4 months, 2 weeks ago
Selected Answer: B
Unit42 through in-depth threat intel investigations understand and grab potential Ransomware behaviors such as common file paths or processes affected in order to build decoy files and enhance the ransomware detection. These decoy files are sent through content updates.
upvoted 1 times
...
nividan
1 year, 4 months ago
Correct Answer: B Behavior-Based Ransomware Protection This module protects against encryption-based behavior associated with ransomware by analyzing and stopping ransomware activity before any data loss occurs. To combat these attacks, Cortex XDR employs decoy files to attract the ransomware. When the ransomware attempts to write to, rename, move, delete, or encrypt the decoy files, the Cortex XDR agent analyzes the behavior and prevents the ransomware from encrypting and holding files hostage. When configured to operate in Prevention Mode, the Cortex XDR agent blocks the process attempting to manipulate the decoy files. When you configure this module in Notification Mode, the agent logs a security event.
upvoted 1 times
...
9smiles
1 year, 8 months ago
My answer would be: B
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago