PCDRA · Question #36
Where would you go to add an exception to exclude a specific file hash from examination by the Malware profile for a Windows endpoint?
The correct answer is B. From the rules menu select new exception, fill out the criteria, choose the scope to apply it to, hit. To add an exception for a specific file hash in Cortex XDR, you navigate to the Rules menu, select 'New Exception,' fill out the criteria (such as the file hash), choose the scope (e.g., specific endpoints or global), and save. This is the correct workflow for creating hash-based
Question
Where would you go to add an exception to exclude a specific file hash from examination by the Malware profile for a Windows endpoint?
Options
- AFind the Malware profile attached to the endpoint, Under Portable Executable and DLL
- BFrom the rules menu select new exception, fill out the criteria, choose the scope to apply it to, hit
- CFind the exceptions profile attached to the endpoint, under process exceptions select local
- DIn the Action Center, choose Allow list, select new action, select add to allow list, add your hash to
How the community answered
(50 responses)- A14% (7)
- B76% (38)
- C4% (2)
- D6% (3)
Explanation
To add an exception for a specific file hash in Cortex XDR, you navigate to the Rules menu, select 'New Exception,' fill out the criteria (such as the file hash), choose the scope (e.g., specific endpoints or global), and save. This is the correct workflow for creating hash-based exceptions in Cortex XDR. Option A is incorrect because the Malware profile itself does not have a direct hash exclusion field under 'Portable Executable and DLL.' Option C is incorrect because process exceptions in the exceptions profile are for process paths, not file hashes. Option D is partially describing the Allow List action, which is a different mechanism used post-alert rather than a proactive exception.
Topics
Community Discussion
No community discussion yet for this question.