nerdexam
Palo_Alto_Networks

XDR-ENGINEER · Question #49

A security audit determines that the Windows Cortex XDR host-based firewall is not blocking outbound RDP connections for certain remote workers. The audit report confirms the following: - All…

The correct answer is D. The pertinent host-based firewall rule group is only applied to internal rule groups. Option D is correct because Network Location is enabled, meaning Cortex XDR classifies endpoints as either internal (corporate network) or external (remote/off-network). If the firewall rule group is configured to apply only to internal network locations, the block rule…

Prevention and Detection

Question

A security audit determines that the Windows Cortex XDR host-based firewall is not blocking outbound RDP connections for certain remote workers. The audit report confirms the following:

  • All devices are running healthy Cortex XDR agents.
  • A single host-based firewall rule to block all outbound RDP is

implemented.

  • The policy hosting the profile containing the rule applies to all

Windows endpoints.

  • The logic within the firewall rule is adequate.
  • Further testing concludes RDP is successfully being blocked on all

devices tested at company HQ.

  • Network location configuration in Agent Settings is enabled on all

Windows endpoints. What is the likely reason the RDP connections are not being blocked?

Options

  • AThe profile's default action for outbound traffic is set to Allow
  • BThe pertinent host-based firewall rule group is only applied to external rule groups
  • CReport mode is set to Enabled in the report settings under the profile configuration
  • DThe pertinent host-based firewall rule group is only applied to internal rule groups

How the community answered

(20 responses)
  • A
    10% (2)
  • B
    5% (1)
  • C
    25% (5)
  • D
    60% (12)

Explanation

Option D is correct because Network Location is enabled, meaning Cortex XDR classifies endpoints as either internal (corporate network) or external (remote/off-network). If the firewall rule group is configured to apply only to internal network locations, the block rule activates at HQ but is never enforced for remote workers on external networks - perfectly matching the described symptoms.

Why the distractors are wrong:

  • A - If the profile's default outbound action were Allow, no location distinction would exist; both HQ and remote workers would be affected equally, so this can't explain the split behavior.
  • B - This is the opposite of D. External-only application would block remote workers but leave HQ unprotected, which is the reverse of what the audit found.
  • C - Report mode would cause the rule to log-only rather than block, but it would apply uniformly to all endpoints regardless of location, so HQ traffic would also be unblocked.

Memory tip: Think of Network Location as a "home vs. office" switch. If you forget to set the rule for both locations, it only enforces where you told it to - just like a key that only works on one door. Whenever a question mentions Network Location is enabled and describes behavior that differs between HQ and remote users, immediately suspect a location-scoped rule group mismatch.

Topics

#host-based firewall#RDP blocking#network location#firewall rule groups

Community Discussion

No community discussion yet for this question.

Full XDR-ENGINEER Practice