PCDRA · Question #15
Where can SHA256 hash values be used in Cortex XDR Malware Protection Profiles?
The correct answer is D. in the Windows Malware Protection Profile to indicate allowed executables. In Cortex XDR, SHA256 hashes can be added to the Windows Malware Protection Profile as an allowlist of trusted executables. This allows security teams to explicitly permit specific files - identified by their unique SHA256 fingerprint - from being blocked by the malware…
Question
Where can SHA256 hash values be used in Cortex XDR Malware Protection Profiles?
Options
- Ain the macOS Malware Protection Profile to indicate allowed signers
- Bin the Linux Malware Protection Profile to indicate allowed Java libraries
- CSHA256 hashes cannot be used in Cortex XDR Malware Protection Profiles
- Din the Windows Malware Protection Profile to indicate allowed executables
How the community answered
(45 responses)- A2% (1)
- C2% (1)
- D96% (43)
Explanation
In Cortex XDR, SHA256 hashes can be added to the Windows Malware Protection Profile as an allowlist of trusted executables. This allows security teams to explicitly permit specific files - identified by their unique SHA256 fingerprint - from being blocked by the malware protection engine. SHA256-based allowlisting is a Windows-specific capability in this context. Linux profiles use different mechanisms (e.g., trusted signers or paths), and macOS profiles use allowed signers (certificates), not hashes.
Topics
Community Discussion
No community discussion yet for this question.