XDR-ENGINEER · Question #49
A security audit determines that the Windows Cortex XDR host-based firewall is not blocking outbound RDP connections for certain remote workers. The audit report confirms the following: - All…
The correct answer is D. The pertinent host-based firewall rule group is only applied to internal rule groups. Option D is correct because Network Location is enabled, meaning Cortex XDR classifies endpoints as either internal (corporate network) or external (remote/off-network). If the firewall rule group is configured to apply only to internal network locations, the block rule…
Question
A security audit determines that the Windows Cortex XDR host-based firewall is not blocking outbound RDP connections for certain remote workers. The audit report confirms the following:
- All devices are running healthy Cortex XDR agents.
- A single host-based firewall rule to block all outbound RDP is
implemented.
- The policy hosting the profile containing the rule applies to all
Windows endpoints.
- The logic within the firewall rule is adequate.
- Further testing concludes RDP is successfully being blocked on all
devices tested at company HQ.
- Network location configuration in Agent Settings is enabled on all
Windows endpoints. What is the likely reason the RDP connections are not being blocked?
Options
- AThe profile's default action for outbound traffic is set to Allow
- BThe pertinent host-based firewall rule group is only applied to external rule groups
- CReport mode is set to Enabled in the report settings under the profile configuration
- DThe pertinent host-based firewall rule group is only applied to internal rule groups
How the community answered
(20 responses)- A10% (2)
- B5% (1)
- C25% (5)
- D60% (12)
Explanation
Option D is correct because Network Location is enabled, meaning Cortex XDR classifies endpoints as either internal (corporate network) or external (remote/off-network). If the firewall rule group is configured to apply only to internal network locations, the block rule activates at HQ but is never enforced for remote workers on external networks - perfectly matching the described symptoms.
Why the distractors are wrong:
- A - If the profile's default outbound action were Allow, no location distinction would exist; both HQ and remote workers would be affected equally, so this can't explain the split behavior.
- B - This is the opposite of D. External-only application would block remote workers but leave HQ unprotected, which is the reverse of what the audit found.
- C - Report mode would cause the rule to log-only rather than block, but it would apply uniformly to all endpoints regardless of location, so HQ traffic would also be unblocked.
Memory tip: Think of Network Location as a "home vs. office" switch. If you forget to set the rule for both locations, it only enforces where you told it to - just like a key that only works on one door. Whenever a question mentions Network Location is enabled and describes behavior that differs between HQ and remote users, immediately suspect a location-scoped rule group mismatch.
Topics
Community Discussion
No community discussion yet for this question.