exam questions

Exam PCDRA All Questions

View all questions & answers for the PCDRA exam

Exam PCDRA topic 1 question 80 discussion

Actual exam question from Palo Alto Networks's PCDRA
Question #: 80
Topic #: 1
[All PCDRA Questions]

Cortex XDR is deployed in the enterprise and you notice a cobalt strike attack via an ongoing supply chain compromise was prevented on 1 server. What steps can you take to ensure the same protection is extended to all your servers?

  • A. Enable DLL Protection on all servers but there might be some false positives.
  • B. Conduct a thorough Endpoint Malware scan.
  • C. Create IOCs of the malicious files you have found to prevent their execution.
  • D. Enable Behavioral Threat Protection (BTP) with cytool to prevent the attack from spreading.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
f6f5c97
1 month, 3 weeks ago
IOC only detected
upvoted 1 times
...
danups
4 months, 1 week ago
Selected Answer: D
- DLL Protection can help, but it might not cover all the behavioral aspects of sophisticated attacks like Cobalt Strike. - Malware Scan is a reactive measure, and not preventive. - IOCs of malicious files can help to detect and prevent but is not as comprehensive as behavioral protection. Right answer here is "D". BTP will prevent any pattern and/or suspicious behavior indicative of an attack.
upvoted 1 times
...
nuna957
8 months, 3 weeks ago
Selected Answer: C
voting is C
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago