PCDRA · Question #70
As a Malware Analyst working with Cortex XDR you notice an alert suggesting that there was a prevented attempt to open a malicious Word document. You learn from the WildFire report and AutoFocus that
The correct answer is D. Install latest content updates to recognize and prevent the activity.. To prevent a known malicious document from being opened by other users, ensure that Cortex XDR agents have the latest content updates, which include updated threat intelligence and detection capabilities.
Question
As a Malware Analyst working with Cortex XDR you notice an alert suggesting that there was a prevented attempt to open a malicious Word document. You learn from the WildFire report and AutoFocus that this document is known to have been used in Phishing campaigns since 2018. What steps can you take to ensure that the same document is not opened by other users in your organization protected by the Cortex XDR agent?
Options
- AEnable DLL Protection on all endpoints but there might be some false positives.
- BNo step is required because Cortex shares IOCs with our fellow Cyber Threat Alliance members.
- CNo step is required because the malicious document is already stopped.
- DInstall latest content updates to recognize and prevent the activity.
How the community answered
(33 responses)- A6% (2)
- B12% (4)
- C3% (1)
- D79% (26)
Why each option
To prevent a known malicious document from being opened by other users, ensure that Cortex XDR agents have the latest content updates, which include updated threat intelligence and detection capabilities.
DLL Protection is a generic feature for preventing malicious DLL injection, not a targeted update specifically for a known malicious document; enabling it broadly might increase false positives unrelated to this specific threat.
While Cortex XDR leverages shared threat intelligence (like WildFire and AutoFocus), the local agent still needs to receive the updated detection content to apply that intelligence proactively.
While the document was stopped on one endpoint, this doesn't guarantee future prevention on all other endpoints without ensuring they have the most current detection mechanisms.
Cortex XDR agents rely on constantly updated content packs (containing signatures, behavioral patterns, and threat intelligence) to recognize and prevent known and emerging threats. By installing the latest content updates, the agent's ability to detect and block this specific, well-known malicious document will be reinforced and deployed across all protected endpoints.
Concept tested: Threat intelligence and content updates in EDR
Source: https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Manage-Content-Updates
Topics
Community Discussion
No community discussion yet for this question.