nerdexam
Palo_Alto_Networks

PCDRA · Question #16

How does Cortex XDR agent for Windows prevent ransomware attacks from compromising the file system?

The correct answer is B. by utilizing decoy Files. Behavior-Based Ransomware Protection This module protects against encryption-based behavior associated with ransomware by analyzing and stopping ransomware activity before any data loss occurs. To combat these attacks, Cortex XDR employs decoy files to attract the ransomware…

Submitted by obi.ng· Apr 18, 2026Cortex XDR Architecture and Agent Deployment

Question

How does Cortex XDR agent for Windows prevent ransomware attacks from compromising the file system?

Options

  • Aby encrypting the disk first.
  • Bby utilizing decoy Files.
  • Cby retrieving the encryption key.
  • Dby patching vulnerable applications.

How the community answered

(33 responses)
  • A
    3% (1)
  • B
    94% (31)
  • D
    3% (1)

Explanation

Behavior-Based Ransomware Protection This module protects against encryption-based behavior associated with ransomware by analyzing and stopping ransomware activity before any data loss occurs. To combat these attacks, Cortex XDR employs decoy files to attract the ransomware. When the ransomware attempts to write to, rename, move, delete, or encrypt the decoy files, the Cortex XDR agent analyzes the behavior and prevents the ransomware from encrypting and holding files hostage. When configured to operate in Prevention Mode, the Cortex XDR agent blocks the process attempting to manipulate the decoy files. When you configure this module in Notification Mode, the agent logs a security event.

Topics

#Cortex XDR agent#Ransomware prevention#Decoy files#Endpoint security

Community Discussion

No community discussion yet for this question.

Full PCDRA Practice