nerdexam
Palo_Alto_Networks

SECOPS-PRO · Question #52

Which response action in Cortex XSIAM would be unavailable to a SOC analyst investigating an incident involving a Linux server?

The correct answer is A. File search and destroy. "File search and destroy" is generally unavailable for Linux servers in Cortex XSIAM due to the lack of native agent-based destructive capabilities on Linux endpoints.

Security Operations Platform Management

Question

Which response action in Cortex XSIAM would be unavailable to a SOC analyst investigating an incident involving a Linux server?

Options

  • AFile search and destroy
  • BLive Terminal session initiation
  • CRunning a script
  • DHalting network access

How the community answered

(37 responses)
  • A
    76% (28)
  • B
    16% (6)
  • C
    5% (2)
  • D
    3% (1)

Explanation

"File search and destroy" is generally unavailable for Linux servers in Cortex XSIAM due to the lack of native agent-based destructive capabilities on Linux endpoints.

Topics

#Cortex XSIAM#Linux endpoint#response actions#file remediation

Community Discussion

No community discussion yet for this question.

Full SECOPS-PRO Practice