PCDRA · Question #38
When investigating security events, which feature in Cortex XDR is useful for reverting the changes on the endpoint?
The correct answer is D. Remediation Suggestions. https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator- Guide/Remediate-Changes-from-Malicious-Activity When investigating suspicious incidents and causality chains you often need to restore and revert changes made to your endpoints as result of a mali
Question
When investigating security events, which feature in Cortex XDR is useful for reverting the changes on the endpoint?
Options
- ARemediation Automation
- BMachine Remediation
- CAutomatic Remediation
- DRemediation Suggestions
How the community answered
(22 responses)- A5% (1)
- B5% (1)
- D91% (20)
Explanation
https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator- Guide/Remediate-Changes-from-Malicious-Activity When investigating suspicious incidents and causality chains you often need to restore and revert changes made to your endpoints as result of a malicious activity. To avoid manually searching for the affected files and registry keys on your endpoints, you can request Cortex XDR for remediation suggestions.
Topics
Community Discussion
No community discussion yet for this question.