XSIAM-ANALYST · Question #42
Based on the image below, which two determinations can be made from the causality chain? (Choose two.)
The correct answer is B. Cortex XDR agent malware profile module applied is set to "Report" mode. D. The process cmd.exe is responsible for the entire chain of execution resulting in the alerts. If you look at the Action field at the bottom left of the alert details, it states "Detected (Reported)". This indicates that the security policy was configured to log the event rather than block it (which would usually say "Blocked" or "Prevented"). In the causality process…
Question
Based on the image below, which two determinations can be made from the causality chain? (Choose two.)
Exhibit
Options
- AThree alerts in total were generated by the agent on the endpoint.
- BCortex XDR agent malware profile module applied is set to "Report" mode.
- CMalware.pdf.exe is responsible for the entire chain of execution resulting in the alerts.
- DThe process cmd.exe is responsible for the entire chain of execution resulting in the alerts.
How the community answered
(54 responses)- A17% (9)
- B76% (41)
- C7% (4)
Explanation
If you look at the Action field at the bottom left of the alert details, it states "Detected (Reported)". This indicates that the security policy was configured to log the event rather than block it (which would usually say "Blocked" or "Prevented"). In the causality process tree, cmd.exe is the parent node on the left, spawning the subsequent processes. The line connects cmd.exe to the two processes on the right, showing it is the "causality group owner" (CGO) responsible for initiating that chain of activity.
Topics
Community Discussion
No community discussion yet for this question.
