Palo_Alto_Networks
PSE-CORTEX · Question #71
A Cortex XSOAR customer has a phishing use case in which a playbook has been implemented with one of the steps blocking a malicious URL found in an email reported by one of the users. What would be…
The correct answer is C. Email the user to confirm the reported email was phishing. See the full explanation below for the reasoning.
Question
A Cortex XSOAR customer has a phishing use case in which a playbook has been implemented with one of the steps blocking a malicious URL found in an email reported by one of the users. What would be the appropriate next step in the playbook?
Options
- AEmail the CISO to advise that malicious email was found.
- BDisable the user's email account.
- CEmail the user to confirm the reported email was phishing.
- DChange the user's password.
How the community answered
(47 responses)- A6% (3)
- B2% (1)
- C83% (39)
- D9% (4)
Community Discussion
No community discussion yet for this question.