nerdexam
Palo_Alto_Networks

XDR-ANALYST · Question #52

An attacker tries to load dynamic libraries on macOS from an unsecure location. Which Cortex XDR module can prevent this attack?

The correct answer is D. Dylib Hijacking. The correct answer is D. Dylib Hijacking. Dylib Hijacking, also known as Dynamic Library Hijacking, is a technique used by attackers to load malicious dynamic libraries on macOS from an unsecure location. This technique takes advantage of the way macOS searches for dynamic…

Endpoint Protection and Agent Capabilities

Question

An attacker tries to load dynamic libraries on macOS from an unsecure location. Which Cortex XDR module can prevent this attack?

Options

  • ADDL Security
  • BHot Patch Protection
  • CKernel Integrity Monitor (KIM)
  • DDylib Hijacking

How the community answered

(41 responses)
  • A
    15% (6)
  • B
    2% (1)
  • C
    10% (4)
  • D
    73% (30)

Explanation

The correct answer is D. Dylib Hijacking. Dylib Hijacking, also known as Dynamic Library Hijacking, is a technique used by attackers to load malicious dynamic libraries on macOS from an unsecure location. This technique takes advantage of the way macOS searches for dynamic libraries to load when an application is executed. To prevent such attacks, Palo Alto Networks offers the Dylib Hijacking prevention capability as part of their Cortex XDR platform. This capability is designed to detect and block attempts to load dynamic libraries from unauthorized or unsecure locations.

Topics

#Dylib Hijacking#macOS protection#dynamic libraries#Cortex XDR modules

Community Discussion

No community discussion yet for this question.

Full XDR-ANALYST Practice