nerdexam
Palo_Alto_Networks

XDR-ANALYST · Question #46

The Cortex XDR console has triggered an incident, blocking a vitally important piece of software in your organization that is known to be benign. Which of the following options would prevent Cortex…

The correct answer is D. Create a global exception. A global exception is a rule that allows you to exclude specific files, processes, or behaviors from being blocked or detected by Cortex XDR. A global exception applies to all endpoints in your organization that are protected by Cortex XDR. Creating a global exception for a…

Cortex XDR Policy and Exception Management

Question

The Cortex XDR console has triggered an incident, blocking a vitally important piece of software in your organization that is known to be benign. Which of the following options would prevent Cortex XDR from blocking this software in the future, for all endpoints in your organization?

Options

  • ACreate an individual alert exclusion.
  • BCreate a global inclusion.
  • CCreate an endpoint-specific exception.
  • DCreate a global exception.

How the community answered

(17 responses)
  • A
    6% (1)
  • B
    6% (1)
  • C
    12% (2)
  • D
    76% (13)

Explanation

A global exception is a rule that allows you to exclude specific files, processes, or behaviors from being blocked or detected by Cortex XDR. A global exception applies to all endpoints in your organization that are protected by Cortex XDR. Creating a global exception for a vitally important piece of software that is known to be benign would prevent Cortex XDR from blocking this software in the future, for all endpoints in your organization. To create a global exception, you need to follow these steps: In the Cortex XDR management console, go to Policy Management > Exceptions and click Add Select the Global Exception option and click Next. Enter a name and description for the exception and click Next. Select the type of exception you want to create, such as file, process, or behavior, and click Next. Specify the criteria for the exception, such as file name, hash, path, process name, command line, or behavior name, and Review the summary of the exception and click Finish.

Topics

#global exception#exclusion policy#false positive remediation#alert management

Community Discussion

No community discussion yet for this question.

Full XDR-ANALYST Practice