nerdexam
Palo_Alto_Networks

XDR-ANALYST · Question #103

As a Malware Analyst working with Cortex XDR you notice an alert suggesting that there was a prevented attempt to download Cobalt Strike on one of your servers. Days later, you learn about a massive…

The correct answer is A. Create Behavioral Threat Protection (BTP) rules to recognize and prevent the activity. To ensure that the same protection is extended to all your servers, you need to create Behavioral Threat Protection (BTP) rules to recognize and prevent the activity. BTP is a feature of Cortex XDR that allows you to create custom rules that detect and block malicious or…

Incident Response and Threat Mitigation

Question

As a Malware Analyst working with Cortex XDR you notice an alert suggesting that there was a prevented attempt to download Cobalt Strike on one of your servers. Days later, you learn about a massive ongoing supply chain attack. Using Cortex XDR you recognize that your server was compromised by the attack and that Cortex XDR prevented it. What steps can you take to ensure that the same protection is extended to all your servers?

Options

  • ACreate Behavioral Threat Protection (BTP) rules to recognize and prevent the activity.
  • BEnable DLL Protection on all servers but there might be some false positives.
  • CCreate IOCs of the malicious files you have found to prevent their execution.
  • DEnable Behavioral Threat Protection (BTP) with cytool to prevent the attack from spreading.

How the community answered

(40 responses)
  • A
    83% (33)
  • B
    3% (1)
  • C
    5% (2)
  • D
    10% (4)

Explanation

To ensure that the same protection is extended to all your servers, you need to create Behavioral Threat Protection (BTP) rules to recognize and prevent the activity. BTP is a feature of Cortex XDR that allows you to create custom rules that detect and block malicious or suspicious behaviors on your endpoints, such as file execution, process injection, network connection, or registry modification. BTP rules can use various operators, functions, and variables to define the criteria and the actions for the rules. By creating BTP rules that match the behaviors of the supply chain attack, you can prevent the attack from compromising your servers.

Topics

#supply chain attack#Behavioral Threat Protection#Cobalt Strike#incident response

Community Discussion

No community discussion yet for this question.

Full XDR-ANALYST Practice