An analyst is investigating a critical incident on a Windows server in which a malware execution led to numerous file deletions and registry key changes. The affected files and registry keys need to be restored efficiently and quickly. Which Cortex XDR response action should the analyst select?
-
A
Execute the Isolate Endpoint action, which automatically reverses all known malware-related changes upon successful isolation.
-
B
Run the Search and Destroy action on all affected endpoints to automatically replace all files with a "good" hash from the content update package.
-
C
Initiate a Live Terminal session and use operating system commands to manually copy original files from a network share and import a clean registry hive.
-
D
Use the Remediation Suggestions action to review and apply the recommended actions for restoring the files and registry values.
Reveal answer details
Close answer details
Correct answerD
ExplanationRemediation Suggestions provides guided, automated recovery actions based on the detected malicious activity, enabling efficient restoration of affected files and registry changes without requiring manual intervention.
Logs are reaching the security platform, but a detection cannot use the source IP because it remains embedded in an unmapped nested field. Which data-processing stage needs correction?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
High-severity detection identifies a process in an unusual directory, but the process is signed by an approved software vendor and may be part of a planned update. What should happen before disposition?
-
A
Compare the evidence and rule logic with the expected update behavior
-
B
Declare malicious activity because high severity removes the need for further validation
-
C
Close the alert as benign because a valid signature establishes expected behavior
-
D
Isolate the endpoint first and inspect evidence only after business impact is known
Reveal answer details
Close answer details
Which artifacts should be collected and analyzed during a forensic investigation following a security operations center (SOC) breach due to a phishing attack?
-
A
IOC logs, BIOC logs, behavior analytics
-
B
Proxy logs, URL logs, cloud audit logs
-
C
SQL injection logs, brute force attack logs, Mimikatz artifacts
-
D
Network traffic logs, event logs, email artifacts
Reveal answer details
Close answer details
Correct answerD
ExplanationNetwork traffic logs, event logs, and email artifacts provide the complete evidence chain for a phishing incident, enabling analysis of the malicious email, user interaction, and resulting system and network activity to reconstruct the attack.
Which resource will provide a definitive, cloud-based verdict on the nature of a suspicious file in Cortex XDR?
-
A
-
B
-
C
-
D
MITRE ATT&CK tactic mapping
Reveal answer details
Close answer details
Correct answerC
ExplanationWildFire provides cloud-based file analysis using sandboxing and advanced threat detection techniques to deliver a definitive verdict on whether a file is malicious, benign, or unknown.
To support data collection, analytics, incident investigation, and response automation, which Cortex XSIAM design should the SOC use?
-
A
Keep each data source and response workflow isolated to prevent shared context
-
B
Start automated response before validating data quality or operational criteria
-
C
Use shared data across analytics, investigation, and governed automation
-
D
Limit the platform to endpoint records and perform all correlation outside it
Reveal answer details
Close answer details
What is the Cortex XSOAR Marketplace?
-
A
Searchable collection of third-party playbooks and data models
-
B
Development environment for creating and sharing third-party integrations
-
C
Digital storefront where Cortex XSOAR training credits can be purchased and used
-
D
Built-in repository of installable content, including integrations and automations
Reveal answer details
Close answer details
Correct answerD
ExplanationThe Cortex XSOAR Marketplace is a built-in repository of installable content, including integrations, playbooks, and automations.
Question 8
Multiple choice
Which two steps belong in the Cortex XSOAR incident lifecycle? (Choose two.)
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answersB, C
ExplanationThe Cortex XSOAR incident lifecycle includes incident creation and incident notification as key steps in managing and responding to incidents.
A custom PowerShell command is detected by Cortex XDR as a behavioral threat, and the administrator has confirmed it as a false positive. What is the most operationally efficient way to allow this command to run and not be detected by Cortex XDR?
-
A
Create an alert exclusion based on CGO hash, signer, and process path.
-
B
Create an alert exception based on CGO process path and command arguments.
-
C
Right click on the alert and create an alert exclusion rule.
-
D
Add the SHA256 hash to the allow list.
Reveal answer details
Close answer details
Correct answerB
ExplanationCreating an alert exception based on CGO process path and command arguments allows the PowerShell command to run without triggering detections, operationally efficiently.
Question 10
Single choice
Which response action in Cortex XSIAM would be unavailable to a SOC analyst investigating an incident involving a Linux server?
-
A
-
B
Live Terminal session initiation
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
Explanation"File search and destroy" is generally unavailable for Linux servers in Cortex XSIAM due to the lack of native agent-based destructive capabilities on Linux endpoints.
Question 11
Single choice
Which attribute applies to script creation in Cortex XSOAR?
-
A
Can be scheduled to run at a later time and day
-
B
Can be executed only with limited permissions
-
C
-
D
Can be protected with a password
Reveal answer details
Close answer details
Correct answerA
ExplanationScripts in Cortex XSOAR can be scheduled to execute at specific times or intervals, enabling automation of tasks without manual initiation.
Question 12
Single choice
Which list accurately identifies out-of-the-box indicator types that can be queried?
-
A
IPv4, URI, Threat Group, Hacking Tool
-
B
Infrastructure, URL, Threat Actor, Tool
-
C
IP Address, Web Link, Adversary, Exploit Kit
-
D
Network Address, Hyperlink, Attacker, Weapon
Reveal answer details
Close answer details
Correct answerB
ExplanationCortex platforms provide predefined indicator types aligned with threat intelligence standards, including Infrastructure, URL, Threat Actor, and Tool, which are available out of the box for querying and analysis.
Question 13
Single choice
Which action should an administrator take to create automated response actions when a user account is compromised?
-
A
Map the events as a type of Cortex XSOAR incident, then run a playbook.
-
B
Create playbook triggers in Cortex XSIAM and run playbooks for each alert.
-
C
Create a script in Cortex XSOAR that will run a playbook based on the scenario.
-
D
Run a custom script from the Cortex XDR script library.
Reveal answer details
Close answer details
Correct answerA
ExplanationAutomated response actions for incidents such as compromised user accounts are implemented in Cortex XSOAR by mapping incoming events to an incident type and associating a playbook with that incident. This enables the playbook to run automatically and execute predefined response actions.
Question 14
Single choice
Before a finding is closed, its remediation owner reports that the vulnerable package was upgraded and marks the change request complete. What should occur next?
-
A
Accept the owner's completion status as sufficient evidence
-
B
Close the finding and validate it during the next annual review
-
C
Rescan or otherwise verify that the affected condition is resolved
-
D
Confirm that the remediation ticket has an assigned completion date
Reveal answer details
Close answer details
Question 15
Single choice
Where can the actions taken to stitch alerts together in Cortex XSIAM be viewed?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationThe causality chain in Cortex XSIAM visualizes alerts stitched together to show the sequence and relationship of events.
Question 16
Single choice
Which Cortex XSOAR capability provides sourcing, download, and management of curated collections of security orchestration content?
-
A
-
B
-
C
Content contribution interface
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationCortex Marketplace is the centralized repository that allows organizations to source, download, and manage curated packs of integrations, playbooks, and other orchestration content.
Question 17
Single choice
Two alerts are waiting for triage. One is a critical-severity detection with low confidence on a noncritical lab host. The other is a high-severity detection with high confidence of active compromise on a payment server. Which alert should receive the higher operational priority?
-
A
The critical-severity alert, because severity alone determines response order
-
B
The critical-severity alert, because low confidence requires the fastest containment
-
C
The high-severity alert, because confidence, active threat context, and asset criticality increase urgency
-
D
The high-severity alert, because operational priority must always be the opposite of detection severity
Reveal answer details
Close answer details
Question 18
Single choice
An incident in Cortex XSIAM displays alerts for "Lsass Memory Dump" originating from a process named proc_dump.exe. The process is unsigned, has an unknown reputation, and was launched from a temporary directory. Which initial verdict applies to this incident?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationAn unsigned process with unknown reputation dumping LSASS memory from a temporary directory is a strong indicator of credential dumping activity, which is malicious and confirms the alert as a true positive.
Question 19
Single choice
What is required to enable ingestion of on-premises firewall logs into Cortex XDR?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationA Broker VM is required to collect and forward on-premises firewall logs to Cortex XDR for ingestion and analysis.
Question 20
Single choice
Organizational policy requires encryption, but a server does not use it. There is no evidence that anyone has exploited the condition. What is directly established?
-
A
Active harmful activity and a confirmed security incident
-
B
A compliance deviation and weakness, but no proven exploitation
-
C
Complete exposure risk, regardless of reachability or asset context
-
D
Formal risk acceptance that removes the need for governance
Reveal answer details
Close answer details
Question 21
Single choice
Which identity security component is best suited to detect lateral movement within a compromised service account?
-
A
-
B
Analytics behavioral indicator of compromise (ABIOC) feature
-
C
-
D
Cortex Identity Threat Detection and Response (ITDR) module
Reveal answer details
Close answer details
Correct answerD
ExplanationCortex Identity Threat Detection and Response (ITDR) is specifically designed to detect identity-based threats such as lateral movement involving compromised service accounts by analyzing authentication patterns, privilege use, and identity behavior across the environment.
|