Network attacks follow predictable patterns. If you interfere with any portion of this pattern, the attack will be neutralized. Which of the following statements is correct?
A.
Cortex XDR Analytics allows to interfere with the pattern as soon as it is observed on the firewall.
B.
Cortex XDR Analytics does not interfere with the pattern as soon as it is observed on the endpoint.
C.
Cortex XDR Analytics does not have to interfere with the pattern as soon as it is observed on the endpoint in order to prevent the attack.
D.
Cortex XDR Analytics allows to interfere with the pattern as soon as it is observed on the endpoint.
If you go here: https://www.paloaltonetworks.com/services/education/palo-alto-networks-certified-detection-and-remediation-analyst
And then go to Sample questions (specifically here: https://www.paloaltonetworks.com/content/dam/pan/en_US/assets/pdf/datasheets/education/pcdra-sample-questions.pdf), there's 7 questions, one of them being:
Which statement is valid regarding the Cortex XDR Analytics module?
A. It interferes with an attack pattern as soon as it is observed on the endpoint.
B. It does not interfere with any portion of the attack pattern on the endpoint.
C. It does not need to interfere with any portion of the pattern to prevent the attack.
D. It interferes with the attack pattern as soon as it is observed on the firewall.
Palo Alto says the answer here is B.
Therefore, for this question on ExamTopics I'd say the answer is B as well.
Coverage of MITRE Attack Tactics:
Network attacks follow predictable patterns. If you interfere with any portion of this pattern, the attack is neutralized.
The Cortex XDR Analytics Engine retrieves logs from the Cortex XDR tenant to create a baseline so that it can raise alerts when abnormal activity occurs. This analysis is highly sophisticated and performed on more than a thousand dimensions of data. Internally, Cortex XDR organizes its analytics activity into algorithms called detectors. Each detector is responsible for raising an alert when suspicious behavior is detected.
https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Analytics-Concepts
So I vote B. It enables the possibility but not to do anything on the Firewall itself or Endpoint itself. So it cannot act as soon as pattern is detected.
Coverage of MITRE Attack Tactics:
Network attacks follow predictable patterns. If you interfere with any portion of this pattern, the attack is neutralized.
The Cortex XDR Analytics Engine retrieves logs from the Cortex XDR tenant to create a baseline so that it can raise alerts when abnormal activity occurs. This analysis is highly sophisticated and performed on more than a thousand dimensions of data. Internally, Cortex XDR organizes its analytics activity into algorithms called detectors. Each detector is responsible for raising an alert when suspicious behavior is detected.
https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Analytics-Concepts
So I vote D. It enables the possibility but not to do anything on the Firewall itself.
The question is talking about Network Attacks, so I think, it is talking about Firewalls,
https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Analytics-Concepts
The Cortex XDR app uses its Analytics Engine to examine logs and data retrieved from your sensors on the Cortex XDR tenants to build an activity baseline, and recognize abnormal activity when it occurs. The Analytics Engine accesses your logs as they are streamed to the Cortex XDR tenant, including any Firewall data, and analyzes the data as soon as it arrives. Cortex XDR raises an Analytics alert when the Analytics Engine determines an anomaly.
I guess the answer is A.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
sharkk43
Highly Voted 8 months, 3 weeks agodeyabeel22
8 months, 3 weeks agoChiquitabandita
Most Recent 4 months agoSpTester
6 months, 2 weeks agoSpTester
6 months, 2 weeks agodarylmaeb24
8 months, 1 week ago_tips
10 months, 1 week agoDavina07
1 year, 1 month ago