SECOPS-PRO · Question #67
During a forensic investigation using Cortex XDR, an analyst discovers a persistent backdoor communicating with an external IP address (192.0. 2.100). The analyst needs to quickly determine if this IP
The correct answer is B. Utilize Cortex XSOAR to orchestrate a lookup of 192 .0.2.100 against multiple integrated threat. Option B represents the most efficient and comprehensive approach. Cortex XSOARs orchestration capabilities allow for automated enrichment of IP addresses using various threat intelligence sources. More importantly, if confirmed malicious, XSOAR can automatically push block rules
Question
During a forensic investigation using Cortex XDR, an analyst discovers a persistent backdoor communicating with an external IP address (192.0. 2.100). The analyst needs to quickly determine if this IP address is associated with known malicious activity and implement a preventative measure. Which of the following actions, leveraging Cortex products, would be the most efficient and comprehensive approach?
Options
- AManually add 192.0.2.100 to a custom Block List on the Next-Generation Firewall (NGFW) and
- BUtilize Cortex XSOAR to orchestrate a lookup of 192 .0.2.100 against multiple integrated threat
- CInitiate a 'Live Response' session in Cortex XDR on affected endpoints to block outbound
- DPerform a 'Packet Capture' in Cortex XDR for all traffic to and from 192.0.2.100 to gather more
- ECreate a new 'Alert Rule' in Cortex XDR specifically for connections to 192.0.2. lee to monitor
How the community answered
(52 responses)- A2% (1)
- B81% (42)
- C12% (6)
- D2% (1)
- E4% (2)
Explanation
Option B represents the most efficient and comprehensive approach. Cortex XSOARs orchestration capabilities allow for automated enrichment of IP addresses using various threat intelligence sources. More importantly, if confirmed malicious, XSOAR can automatically push block rules to NGFWs, ensuring network-wide prevention. Option A involves manual steps and doesn't leverage the full automation potential. Option C is a per-endpoint solution, not network-wide. Option D is an investigative step, not a preventative measure. Option E is monitoring, not blocking.
Topics
Community Discussion
No community discussion yet for this question.