nerdexam
Palo_Alto_Networks

SECOPS-PRO · Question #50

Which task should a threat hunter include in the investigation when a Cortex XDR incident contains alertsout a malicious process?

The correct answer is B. Search for the SHA256 file hash on other endpoints in the environment. Searching for the SHA256 file hash across other endpoints helps identify lateral spread and scope of the malicious process, essential for threat hunting.

Threat Hunting and Incident Response

Question

Which task should a threat hunter include in the investigation when a Cortex XDR incident contains alertsout a malicious process?

Options

  • AImmediately isolate the endpoint and delete the identified file.
  • BSearch for the SHA256 file hash on other endpoints in the environment.
  • CAdd the SHA256 file hash to the Cortex XDR global block list.
  • DDisable the account of the user responsible for initiating the process.

How the community answered

(28 responses)
  • A
    11% (3)
  • B
    79% (22)
  • C
    4% (1)
  • D
    7% (2)

Explanation

Searching for the SHA256 file hash across other endpoints helps identify lateral spread and scope of the malicious process, essential for threat hunting.

Topics

#threat hunting#SHA256 hash#endpoint investigation#malicious process

Community Discussion

No community discussion yet for this question.

Full SECOPS-PRO Practice