SECOPS-PRO · Question #66
A Security Operations Center (SOC) using Cortex XDR observes a high-severity alert indicating a potential ransomware attack. The alert details include a specific file hash (SHA256: e3bOc44298fc1c149af
The correct answer is A. Automatically querying AutoFocus for intelligence on the file hash to determine its reputation and. Option A is the most effective. Cortex XDR integrates with AutoFocus, Palo Alto Networks' threat intelligence service, which can provide immediate context and reputation for file hashes. If the hash is known malicious, WildFire (Palo Alto Networks' cloud-delivered malware analysi
Question
A Security Operations Center (SOC) using Cortex XDR observes a high-severity alert indicating a potential ransomware attack. The alert details include a specific file hash (SHA256:
e3bOc44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855) associated with a suspicious process. Which of the following Cortex XDR and Cortex XSOAR capabilities would be most effective in leveraging this file indicator for rapid investigation and containment?
Options
- AAutomatically querying AutoFocus for intelligence on the file hash to determine its reputation and
- BUsing the file hash in a Cortex XDR 'Live Terminal' session to remotely delete the suspicious file
- CConfiguring a custom 'Exclusion' in Cortex XDR for this specific file hash to prevent future alerts.
- DLeveraging a Cortex XSOAR playbook to initiate a 'War Room' discussion with the incident
- ESubmitting the file hash to the public VirusTotal API and awaiting a community verdict before
How the community answered
(17 responses)- A76% (13)
- C6% (1)
- D12% (2)
- E6% (1)
Explanation
Option A is the most effective. Cortex XDR integrates with AutoFocus, Palo Alto Networks' threat intelligence service, which can provide immediate context and reputation for file hashes. If the hash is known malicious, WildFire (Palo Alto Networks' cloud-delivered malware analysis service) can be used to generate a signature and prevent execution, effectively blocking it across the network. This demonstrates the seamless integration of file indicators for rapid threat intelligence lookup and prevention. Option B is a reactive measure, and deleting a file without full context can be risky. Option C is incorrect; you would want to block, not exclude, a malicious file. Option D is a procedural step but doesn't directly leverage the file indicator for technical containment. Option E relies on external, potentially slower public services.
Topics
Community Discussion
No community discussion yet for this question.