PCDRA · Question #90
A Linux endpoint with a Cortex XDR Pro per Endpoint license and Enhanced Endpoint Data enabled has reported malicious activity, resulting in the creation of a file that you wish to delete. Which actio
The correct answer is C. Initiate Remediate Suggestions to automatically delete the file.. With a Cortex XDR Pro per Endpoint license and Enhanced Endpoint Data enabled, the 'Remediation Suggestions' feature becomes available. This Cortex XDR native capability automatically analyzes detected malicious activity and proposes - or can automatically execute - remediation a
Question
A Linux endpoint with a Cortex XDR Pro per Endpoint license and Enhanced Endpoint Data enabled has reported malicious activity, resulting in the creation of a file that you wish to delete. Which action could you take to delete the file?
Options
- AManually remediate the problem on the endpoint in question.
- BOpen X2go from the Cortex XDR console and delete the file via X2go.
- CInitiate Remediate Suggestions to automatically delete the file.
- DOpen an NFS connection from the Cortex XDR console and delete the file.
How the community answered
(52 responses)- A6% (3)
- B2% (1)
- C81% (42)
- D12% (6)
Explanation
With a Cortex XDR Pro per Endpoint license and Enhanced Endpoint Data enabled, the 'Remediation Suggestions' feature becomes available. This Cortex XDR native capability automatically analyzes detected malicious activity and proposes - or can automatically execute - remediation actions such as deleting malicious files, quarantining processes, or removing registry keys. For a Linux endpoint, this is the correct in-console approach. Option A (manual remediation) implies physical or out-of-band access. Option B (X2go) and Option D (NFS) are not Cortex XDR features - they are general remote access protocols not integrated into the Cortex XDR console.
Topics
Community Discussion
No community discussion yet for this question.