Palo_Alto_Networks
SECOPS-PRO · Question #50
Which task should a threat hunter include in the investigation when a Cortex XDR incident contains alertsout a malicious process?
The correct answer is B. Search for the SHA256 file hash on other endpoints in the environment. Searching for the SHA256 file hash across other endpoints helps identify lateral spread and scope of the malicious process, essential for threat hunting.
Threat Hunting and Incident Response
Question
Which task should a threat hunter include in the investigation when a Cortex XDR incident contains alertsout a malicious process?
Options
- AImmediately isolate the endpoint and delete the identified file.
- BSearch for the SHA256 file hash on other endpoints in the environment.
- CAdd the SHA256 file hash to the Cortex XDR global block list.
- DDisable the account of the user responsible for initiating the process.
How the community answered
(28 responses)- A11% (3)
- B79% (22)
- C4% (1)
- D7% (2)
Explanation
Searching for the SHA256 file hash across other endpoints helps identify lateral spread and scope of the malicious process, essential for threat hunting.
Topics
#threat hunting#SHA256 hash#endpoint investigation#malicious process
Community Discussion
No community discussion yet for this question.