exam questions

Exam PCDRA All Questions

View all questions & answers for the PCDRA exam

Exam PCDRA topic 1 question 4 discussion

Actual exam question from Palo Alto Networks's PCDRA
Question #: 4
Topic #: 1
[All PCDRA Questions]

What are two purposes of “Respond to Malicious Causality Chains” in a Cortex XDR Windows Malware profile? (Choose two.)

  • A. Automatically close the connections involved in malicious traffic.
  • B. Automatically kill the processes involved in malicious activity.
  • C. Automatically terminate the threads involved in malicious activity.
  • D. Automatically block the IP addresses involved in malicious traffic.
Show Suggested Answer Hide Answer
Suggested Answer: AD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
kadirerol
3 months, 3 weeks ago
ın depend of below document I selected answer AD.
upvoted 1 times
...
news088
1 year, 2 months ago
selected answer AD https://live.paloaltonetworks.com/t5/community-blogs/cortex-xdr-agent-7-3-new-features/ba-p/383329
upvoted 2 times
...
sharkk43
1 year, 2 months ago
Selected Answer: AD
I say it's A and D because of what I'm just reading off the official course in the section "Respond to Malicious Causality Chains". It goes like this: "When the Cortex XDR agent detects a malicious activity, the Respond to Malicious Causality Chains module inspects the network connections opened by the processes involved in the attack to identify malicious IP addresses." To me that's A nd D not A and C.
upvoted 3 times
sharkk43
1 year, 2 months ago
Forgot to add the second part: "If such network connections are found, this protection module can automatically close all the network connections and block new connection requests from these IP addresses."
upvoted 3 times
...
...
XuannnnOAO
1 year, 3 months ago
CD is correct
upvoted 1 times
...
unns12
1 year, 4 months ago
CD is correct
upvoted 2 times
...
Karreldanam
1 year, 7 months ago
Selected Answer: AD
(Windows only) Respond to Malicious Causality Chains. When the Cortex XDR agent identifies a remote network connection that attempts to perform malicious activity—such as encrypting endpoint files—the agent can automatically block the IP address to close all existing communication and block new connections from this IP address to the endpoint. When Cortex XDRblocks an IP address per endpoint, that address remains blocked throughout all agent profiles and policies, including any host-firewall policy rules. You can view the list of all blocked IP addresses per endpoint from the Action Center, as well as unblock them to re-enable communication as appropriate.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago