nerdexam
Palo_Alto_Networks

XSIAM-ANALYST · Question #8

An analyst is responding to a critical incident involving a potential ransomware attack. The analyst immediately initiates full isolation on the compromised endpoint using Cortex XSIAM to prevent…

The correct answer is B. Collecting the evidence manually through the agent by accessing the machine directly and. In situations where full isolation is enabled on an endpoint, all network communication is completely restricted. To ensure that the endpoint remains isolated while still obtaining forensic evidence such as memory dumps or disk images, the analyst needs to use manual collection…

Incident Investigation and Response

Question

An analyst is responding to a critical incident involving a potential ransomware attack. The analyst immediately initiates full isolation on the compromised endpoint using Cortex XSIAM to prevent the malware from spreading across the network. However, the analyst now needs to collect additional forensic evidence from the isolated machine, including memory dumps and disk images, without reconnecting it to the network. Which action will allow the analyst to collect the required forensic evidence while ensuring the endpoint remains fully isolated?

Options

  • AUsing the management console to remotely run a predefined forensic playbook on the associated
  • BCollecting the evidence manually through the agent by accessing the machine directly and
  • CUsing the endpoint isolation feature to create a secure tunnel for evidence collection
  • DDisabling full isolation temporarily to allow forensic tools to communicate with the endpoint

How the community answered

(22 responses)
  • A
    14% (3)
  • B
    50% (11)
  • C
    32% (7)
  • D
    5% (1)

Explanation

In situations where full isolation is enabled on an endpoint, all network communication is completely restricted. To ensure that the endpoint remains isolated while still obtaining forensic evidence such as memory dumps or disk images, the analyst needs to use manual collection via the agent directly on the machine. The "Generate Support File" feature within the agent allows analysts to locally gather detailed forensic data without breaking network isolation. This manual method ensures the endpoint does not reconnect or communicate externally, maintaining strict isolation for security purposes. "In endpoint isolation mode, network communication is completely blocked. Analysts should utilize the local 'Generate Support File' function on the agent to collect forensic data while maintaining full isolation."

Topics

#endpoint isolation#forensic evidence#ransomware response#incident containment

Community Discussion

No community discussion yet for this question.

Full XSIAM-ANALYST Practice