nerdexam
Palo_Alto_Networks

SECOPS-PRO · Question #67

During a forensic investigation using Cortex XDR, an analyst discovers a persistent backdoor communicating with an external IP address (192.0. 2.100). The analyst needs to quickly determine if this IP

The correct answer is B. Utilize Cortex XSOAR to orchestrate a lookup of 192 .0.2.100 against multiple integrated threat. Option B represents the most efficient and comprehensive approach. Cortex XSOARs orchestration capabilities allow for automated enrichment of IP addresses using various threat intelligence sources. More importantly, if confirmed malicious, XSOAR can automatically push block rules

Threat Intelligence and Incident Response

Question

During a forensic investigation using Cortex XDR, an analyst discovers a persistent backdoor communicating with an external IP address (192.0. 2.100). The analyst needs to quickly determine if this IP address is associated with known malicious activity and implement a preventative measure. Which of the following actions, leveraging Cortex products, would be the most efficient and comprehensive approach?

Options

  • AManually add 192.0.2.100 to a custom Block List on the Next-Generation Firewall (NGFW) and
  • BUtilize Cortex XSOAR to orchestrate a lookup of 192 .0.2.100 against multiple integrated threat
  • CInitiate a 'Live Response' session in Cortex XDR on affected endpoints to block outbound
  • DPerform a 'Packet Capture' in Cortex XDR for all traffic to and from 192.0.2.100 to gather more
  • ECreate a new 'Alert Rule' in Cortex XDR specifically for connections to 192.0.2. lee to monitor

How the community answered

(52 responses)
  • A
    2% (1)
  • B
    81% (42)
  • C
    12% (6)
  • D
    2% (1)
  • E
    4% (2)

Explanation

Option B represents the most efficient and comprehensive approach. Cortex XSOARs orchestration capabilities allow for automated enrichment of IP addresses using various threat intelligence sources. More importantly, if confirmed malicious, XSOAR can automatically push block rules to NGFWs, ensuring network-wide prevention. Option A involves manual steps and doesn't leverage the full automation potential. Option C is a per-endpoint solution, not network-wide. Option D is an investigative step, not a preventative measure. Option E is monitoring, not blocking.

Topics

#Cortex XSOAR#IP reputation lookup#threat intelligence orchestration#automated blocking

Community Discussion

No community discussion yet for this question.

Full SECOPS-PRO Practice