XDR-ANALYST · Question #103
As a Malware Analyst working with Cortex XDR you notice an alert suggesting that there was a prevented attempt to download Cobalt Strike on one of your servers. Days later, you learn about a massive…
The correct answer is A. Create Behavioral Threat Protection (BTP) rules to recognize and prevent the activity. To ensure that the same protection is extended to all your servers, you need to create Behavioral Threat Protection (BTP) rules to recognize and prevent the activity. BTP is a feature of Cortex XDR that allows you to create custom rules that detect and block malicious or…
Question
As a Malware Analyst working with Cortex XDR you notice an alert suggesting that there was a prevented attempt to download Cobalt Strike on one of your servers. Days later, you learn about a massive ongoing supply chain attack. Using Cortex XDR you recognize that your server was compromised by the attack and that Cortex XDR prevented it. What steps can you take to ensure that the same protection is extended to all your servers?
Options
- ACreate Behavioral Threat Protection (BTP) rules to recognize and prevent the activity.
- BEnable DLL Protection on all servers but there might be some false positives.
- CCreate IOCs of the malicious files you have found to prevent their execution.
- DEnable Behavioral Threat Protection (BTP) with cytool to prevent the attack from spreading.
How the community answered
(40 responses)- A83% (33)
- B3% (1)
- C5% (2)
- D10% (4)
Explanation
To ensure that the same protection is extended to all your servers, you need to create Behavioral Threat Protection (BTP) rules to recognize and prevent the activity. BTP is a feature of Cortex XDR that allows you to create custom rules that detect and block malicious or suspicious behaviors on your endpoints, such as file execution, process injection, network connection, or registry modification. BTP rules can use various operators, functions, and variables to define the criteria and the actions for the rules. By creating BTP rules that match the behaviors of the supply chain attack, you can prevent the attack from compromising your servers.
Topics
Community Discussion
No community discussion yet for this question.