PCDRA · Question #83
In Windows and macOS you need to prevent the Cortex XDR Agent from blocking execution of a file based on the digital signer. What is one way to add an exception for the singer?
The correct answer is C. Add the signer to the allow list in the malware profile.. In Cortex XDR, the Malware Security Profile contains allow list configurations for trusted signers. By adding a digital signer's certificate (e.g., a specific code-signing certificate or publisher name) to the allow list within the malware profile, the agent will trust any file s
Question
In Windows and macOS you need to prevent the Cortex XDR Agent from blocking execution of a file based on the digital signer. What is one way to add an exception for the singer?
Options
- AIn the Restrictions Profile, add the file name and path to the Executable Files allow list.
- BCreate a new rule exception and use the singer as the characteristic.
- CAdd the signer to the allow list in the malware profile.
- DAdd the signer to the allow list under the action center page.
How the community answered
(24 responses)- A4% (1)
- B4% (1)
- C92% (22)
Explanation
In Cortex XDR, the Malware Security Profile contains allow list configurations for trusted signers. By adding a digital signer's certificate (e.g., a specific code-signing certificate or publisher name) to the allow list within the malware profile, the agent will trust any file signed by that signer and skip blocking it. Adding a file name and path to the Executable Files allow list in the Restrictions Profile (A) is path/name-based, not signer-based. Creating a rule exception using the signer as a characteristic (B) is not a supported workflow for signer-based exceptions in this way. The Action Center page (D) is for reviewing and managing past alerts, not for configuring ongoing allow list policies.
Topics
Community Discussion
No community discussion yet for this question.