nerdexam
Palo_Alto_Networks

PCDRA · Question #15

Where can SHA256 hash values be used in Cortex XDR Malware Protection Profiles?

The correct answer is D. in the Windows Malware Protection Profile to indicate allowed executables. In Cortex XDR, SHA256 hashes can be added to the Windows Malware Protection Profile as an allowlist of trusted executables. This allows security teams to explicitly permit specific files - identified by their unique SHA256 fingerprint - from being blocked by the malware…

Submitted by fernanda_arg· Apr 18, 2026Cortex XDR Architecture and Agent Deployment

Question

Where can SHA256 hash values be used in Cortex XDR Malware Protection Profiles?

Options

  • Ain the macOS Malware Protection Profile to indicate allowed signers
  • Bin the Linux Malware Protection Profile to indicate allowed Java libraries
  • CSHA256 hashes cannot be used in Cortex XDR Malware Protection Profiles
  • Din the Windows Malware Protection Profile to indicate allowed executables

How the community answered

(45 responses)
  • A
    2% (1)
  • C
    2% (1)
  • D
    96% (43)

Explanation

In Cortex XDR, SHA256 hashes can be added to the Windows Malware Protection Profile as an allowlist of trusted executables. This allows security teams to explicitly permit specific files - identified by their unique SHA256 fingerprint - from being blocked by the malware protection engine. SHA256-based allowlisting is a Windows-specific capability in this context. Linux profiles use different mechanisms (e.g., trusted signers or paths), and macOS profiles use allowed signers (certificates), not hashes.

Topics

#Cortex XDR#Malware Protection Profiles#SHA256 Whitelisting#Allowed Executables

Community Discussion

No community discussion yet for this question.

Full PCDRA Practice