It's B as its only asking create an exception for Windows Endpoint.Can't be D as it will create exeption for all endpoint regardless of the Platform Type.
D: Investigate Files:
You can manage file execution on your endpoints by using file hashes that are included in
your allow and block lists. If you trust a certain file and know it to be benign, you can add the
file hash to the allow list and allow it to be executed on all your endpoints regardless of the
WildFire or local analysis verdict. Similarly, if you want to always block a file from running on
any of your endpoints, you can add the associated hash to the block list.
I say B based on: https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Add-an-IOC-or-BIOC-Rule-Exception
"If you want to create a rule to take action on specific behaviors but also want to exclude one or more indicators from the rule, you can create an IOC or BIOC rule exception. An indicator can include the SHA256 hash of a process, process name, process path, vendor name, user name, causality group owner (CGO) full path, or process command-line arguments. For more information about these indicators, see Rules. For each exception, you also specify the rule scope to which the exception applies."
"Select Settings → Exception Configuration → IOC/BIOC Suppression Rules.
Click + New Exception.
Specify a Rule Name and an optional Description.
etc."
2.3.3 Outline malware protection flow
https://www.paloaltonetworks.com/content/dam/pan/en_US/assets/pdf/datasheets/education/pcdra-study-guide.pdf
Hash exception - A hash exception enables you to override the verdict for a specific file
without affecting the settings in your Malware Security profile. The Hash Exception policy is
evaluated first and takes precedence over all other methods to determine the hash verdict.
The exception does not allow Hash value
upvoted 2 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Zubair2131
4 months, 1 week agodarylmaeb24
7 months, 3 weeks agodeyabeel22
8 months, 3 weeks agosharkk43
8 months, 3 weeks ago_tips
10 months, 1 week ago