nerdexam
Palo_Alto_Networks

XSIAM-ANALYST · Question #23

A security analyst has been assigned a ticket from the help desk stating that users are experiencing errors when attempting to open files on a specific network share. These errors state that the…

The correct answer is D. Known Vulnerable Process Protection. Known Vulnerable Process Protection in Cortex XSIAM is specifically designed to block or restrict execution of well-known attack tools and processes such as Mimikatz. This profile allows you to enforce an Action Mode of "Block" to prevent such tools from running, even if they…

Endpoint Protection Policies

Question

A security analyst has been assigned a ticket from the help desk stating that users are experiencing errors when attempting to open files on a specific network share. These errors state that the file format cannot be opened. IT has verified that the file server is online and functioning, but that all files have unusual extensions attached to them. The security analyst reviews alerts within Cortex XSIAM and identifies malicious activity related to a possible ransomware attack on the file server. This incident is then escalated to the incident response team for further investigation. Upon reviewing the incident, the responders confirm that ransomware was successfully executed on the file server. Other details of the attack are noted below:

  • An unpatched vulnerability on an externally facing web server was

exploited for initial access

  • The attackers successfully used Mimikatz to dump sensitive

credentials that were used for privilege escalation

  • PowerShell was used on a Windows server for additional discovery, as

well as lateral movement to other systems

  • The attackers executed SystemBC RAT on multiple systems to maintain

remote access

  • Ransomware payload was downloaded on the file server via an external

site, "file.io" Refer to the scenario to answer this question:

The incident responders are attempting to determine why Mimikatz was able to successfully run during the attack. Which exploit protection profile in Cortex XSIAM should be reviewed to ensure it is configured with an Action Mode of Block?

Options

  • AOperating System Exploit Protection
  • BBrowser Exploits Protection
  • CLogical Exploits Protection
  • DKnown Vulnerable Process Protection

How the community answered

(49 responses)
  • A
    2% (1)
  • C
    2% (1)
  • D
    96% (47)

Explanation

Known Vulnerable Process Protection in Cortex XSIAM is specifically designed to block or restrict execution of well-known attack tools and processes such as Mimikatz. This profile allows you to enforce an Action Mode of "Block" to prevent such tools from running, even if they are executed as part of a privilege escalation or credential dumping attack. "The Known Vulnerable Process Protection profile can be configured to block processes like Mimikatz, preventing credential dumping tools from running on protected endpoints."

Topics

#Ransomware Protection#Known Vulnerable Process#Exploit Protection#Endpoint Security

Community Discussion

No community discussion yet for this question.

Full XSIAM-ANALYST Practice