Cortex XSOAR has extracted a malicious Internet Protocol (IP) address involved in command-and-control (C2) traffic. What is the best method to block this IP from communicating with endpoints without requiring a configuration change on the firewall?
A.
Have XSOAR automatically add the IP address to a threat intelligence management (TIM) malicious IP list to elevate priority of future alerts.
B.
Have XSOAR automatically add the IP address to a deny rule in the firewall.
C.
Have XSOAR automatically add the IP address to an external dynamic list (EDL) used by the firewall.
Most Voted
D.
Have XSOAR automatically create a NetOps ticket requesting a configuration change to the firewall to block the IP.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
engineerpe25
1 week ago5688ac9
8 months, 3 weeks ago