PCCET · Question #41
In addition to local analysis, what can send unknown files to WildFire for discovery and deeper analysis to rapidly detect potentially unknown malware?
The correct answer is A. Cortex XDR. Cortex XDR integrates with WildFire, Palo Alto Networks' cloud-based threat analysis service. When Cortex XDR encounters an unknown or suspicious file on an endpoint that cannot be conclusively classified through local analysis, it automatically submits the file to WildFire for…
Question
In addition to local analysis, what can send unknown files to WildFire for discovery and deeper analysis to rapidly detect potentially unknown malware?
Options
- ACortex XDR
- BAutoFocus
- CMineMild
- DCortex XSOAR
How the community answered
(48 responses)- A96% (46)
- B2% (1)
- D2% (1)
Explanation
Cortex XDR integrates with WildFire, Palo Alto Networks' cloud-based threat analysis service. When Cortex XDR encounters an unknown or suspicious file on an endpoint that cannot be conclusively classified through local analysis, it automatically submits the file to WildFire for deeper, dynamic and static analysis in a sandboxed environment. This enables rapid discovery of previously unknown ('zero-day') malware. AutoFocus provides threat intelligence context. MineMeld aggregates threat intelligence feeds. Cortex XSOAR orchestrates response workflows - none of these natively perform the local-to-WildFire file submission workflow the way Cortex XDR does.
Topics
Community Discussion
No community discussion yet for this question.