Palo_Alto_Networks
PSE-CORTEX · Question #69
Cortex XSOAR has extracted a malicious Internet Protocol (IP) address involved in command- and-control (C2) traffic. What is the best method to block this IP from communicating with endpoints…
The correct answer is C. Have XSOAR automatically add the IP address to an external dynamic list (EDL) used by the. See the full explanation below for the reasoning.
Question
Cortex XSOAR has extracted a malicious Internet Protocol (IP) address involved in command- and-control (C2) traffic. What is the best method to block this IP from communicating with endpoints without requiring a configuration change on the firewall?
Options
- AHave XSOAR automatically add the IP address to a threat intelligence management (TIM)
- BHave XSOAR automatically add the IP address to a deny rule in the firewall.
- CHave XSOAR automatically add the IP address to an external dynamic list (EDL) used by the
- DHave XSOAR automatically create a NetOps ticket requesting a configuration change to the
How the community answered
(24 responses)- A13% (3)
- B8% (2)
- C75% (18)
- D4% (1)
Community Discussion
No community discussion yet for this question.