PCDRA · Question #4
What are two purposes of "Respond to Malicious Causality Chains" in a Cortex XDR Windows Malware profile? (Choose two.)
The correct answer is A. Automatically close the connections involved in malicious traffic. D. Automatically block the IP addresses involved in malicious traffic.. In a Cortex XDR Windows Malware Security Profile, the 'Respond to Malicious Causality Chains' feature enables the agent to take automated network-level response actions when a malicious causality chain is detected. Specifically, it can automatically close the network connections
Question
What are two purposes of "Respond to Malicious Causality Chains" in a Cortex XDR Windows Malware profile? (Choose two.)
Options
- AAutomatically close the connections involved in malicious traffic.
- BAutomatically kill the processes involved in malicious activity.
- CAutomatically terminate the threads involved in malicious activity.
- DAutomatically block the IP addresses involved in malicious traffic.
How the community answered
(57 responses)- A91% (52)
- B5% (3)
- C4% (2)
Explanation
In a Cortex XDR Windows Malware Security Profile, the 'Respond to Malicious Causality Chains' feature enables the agent to take automated network-level response actions when a malicious causality chain is detected. Specifically, it can automatically close the network connections involved in malicious traffic (A) and automatically block the IP addresses associated with that malicious traffic (D). These responses cut off the attacker's communication channel at the network level. Killing processes (B) and terminating threads (C) are process-level response actions associated with other response mechanisms in XDR profiles, not the specific purpose of the Malicious Causality Chain response feature.
Topics
Community Discussion
No community discussion yet for this question.