nerdexam
Palo_Alto_Networks

SECOPS-PRO · Question #68

A sophisticated APT group is observed using a custom, polymorphic malware variant. The only consistent indicator found across initial compromises is the use of a unique, newly registered domain (evil-

The correct answer is B. Ingest the domain into a custom 'Threat Intelligence Feed' within Cortex XSOAR, which then. Option B is the most robust and automated solution. Ingesting the domain into a custom XSOAR threat intelligence feed allows for centralized management and automated distribution to NGFW EDLs for immediate network-wide blocking. Simultaneously, creating an Analytics Rule in XDR e

Threat Intelligence Operations

Question

A sophisticated APT group is observed using a custom, polymorphic malware variant. The only consistent indicator found across initial compromises is the use of a unique, newly registered domain (evil-command-control.xyz) for C2 communications, which is not yet widely known to public threat intelligence feeds. The security team needs to rapidly operationalize this domain indicator within their Cortex ecosystem for both prevention and detection.

Options

  • ASubmit the domain to WildFire for analysis and await a verdict, then manually create a custom
  • BIngest the domain into a custom 'Threat Intelligence Feed' within Cortex XSOAR, which then
  • CLeverage Cortex XDR's 'Indicator Management' to directly import the domain. This will
  • DModify the existing 'DNS Security Policy' on the NGFW to block all queries to .xyz top-level
  • ECreate a custom 'AutoFocus Profile' for the domain evil-command-control.xyz and then use

How the community answered

(43 responses)
  • A
    2% (1)
  • B
    72% (31)
  • C
    2% (1)
  • D
    9% (4)
  • E
    14% (6)

Explanation

Option B is the most robust and automated solution. Ingesting the domain into a custom XSOAR threat intelligence feed allows for centralized management and automated distribution to NGFW EDLs for immediate network-wide blocking. Simultaneously, creating an Analytics Rule in XDR ensures continuous detection and alerting on any attempts to connect to or resolve the domain on endpoints. This provides both proactive prevention and reactive detection. Option A is too manual and reactive. Option C is incorrect; while XDR can use indicators, direct automatic blocking across the network based solely on indicator import isn't its primary mechanism without an NGFW integration or specific policy. Option D is overly broad and would cause legitimate service disruption. Option E is an investigative step and doesn't provide automated prevention or detection.

Topics

#Cortex XSOAR#custom threat intelligence feed#C2 domain#indicator operationalization

Community Discussion

No community discussion yet for this question.

Full SECOPS-PRO Practice