nerdexam
Palo_Alto_Networks

PSE-CORTEX · Question #69

Cortex XSOAR has extracted a malicious Internet Protocol (IP) address involved in command- and-control (C2) traffic. What is the best method to block this IP from communicating with endpoints…

The correct answer is C. Have XSOAR automatically add the IP address to an external dynamic list (EDL) used by the. See the full explanation below for the reasoning.

Question

Cortex XSOAR has extracted a malicious Internet Protocol (IP) address involved in command- and-control (C2) traffic. What is the best method to block this IP from communicating with endpoints without requiring a configuration change on the firewall?

Options

  • AHave XSOAR automatically add the IP address to a threat intelligence management (TIM)
  • BHave XSOAR automatically add the IP address to a deny rule in the firewall.
  • CHave XSOAR automatically add the IP address to an external dynamic list (EDL) used by the
  • DHave XSOAR automatically create a NetOps ticket requesting a configuration change to the

How the community answered

(24 responses)
  • A
    13% (3)
  • B
    8% (2)
  • C
    75% (18)
  • D
    4% (1)

Community Discussion

No community discussion yet for this question.

Full PSE-CORTEX Practice