Question 1
Multiple choice
When reaching out to TAC for additional technical support related to a Security Event; what are two critical pieces of information you need to collect from the Agent? (Choose Two)
-
A
The agent technical support file.
-
B
The prevention archive from the alert.
-
C
The distribution id of the agent.
-
D
A list of all the current exceptions applied to the agent.
-
E
Reveal answer details
Close answer details
Correct answersA, B
ExplanationWhen reaching out to TAC for additional technical support related to a security event, two critical pieces of information you need to collect from the agent are: The agent technical support file. This is a file that contains diagnostic information about the agent, such as its configuration, status, logs, and system information. The agent technical support file can help TAC troubleshoot and resolve issues with the agent or the endpoint. You can generate and download the agent technical support file from the Cortex XDR console, or from the agent itself. The prevention archive from the alert. This is a file that contains forensic data related to the alert, such as the process tree, the network activity, the registry changes, and the files involved. The prevention archive can help TAC analyze and understand the alert and the malicious activity. You can generate and download the prevention archive from the Cortex XDR console, or from the agent itself. The other options are not critical pieces of information for TAC, and may not be available or relevant for every security event. For example: The distribution id of the agent is a unique identifier that is assigned to the agent when it is installed on the endpoint. The distribution id can help TAC identify the agent and its profile, but it is not sufficient to provide technical support or forensic analysis. The distribution id can be found in the Cortex XDR console, or in the agent installation folder. A list of all the current exceptions applied to the agent is a set of rules that define the files, processes, or behaviors that are excluded from the agent's security policies. The exceptions can help TAC understand the agent's configuration and behavior, but they are not essential to provide technical support or forensic analysis. The exceptions can be found in the Cortex XDR console, or in the agent configuration file. The unique agent id is a unique identifier that is assigned to the agent when it registers with Cortex XDR. The unique agent id can help TAC identify the agent and its endpoint, but it is not sufficient to provide technical support or forensic analysis. The unique agent id can be found in the Cortex XDR console, or in the agent log file. Generate and Download the Agent Technical Support File Generate and Download the Prevention Archive Cortex XDR Agent Administrator Guide: Agent Distribution ID Cortex XDR Agent Administrator Guide: Exception Security Profiles [Cortex XDR Agent Administrator Guide: Unique Agent ID]
Which of the following is NOT an option when filtering incidents in the Cortex XDR console?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationIn Cortex XDR, filtering incidents by severity, assigned analyst, and incident age are valid. However, incidents cannot be directly filtered by file type. Option D is incorrect as it is not a valid incident filter criteria.
As a Malware Analyst working with Cortex XDR you notice an alert suggesting that there was a prevented attempt to download Cobalt Strike on one of your servers. Days later, you learn about a massive ongoing supply chain attack. Using Cortex XDR you recognize that your server was compromised by the attack and that Cortex XDR prevented it. What steps can you take to ensure that the same protection is extended to all your servers?
-
A
Create Behavioral Threat Protection (BTP) rules to recognize and prevent the activity.
-
B
Enable DLL Protection on all servers but there might be some false positives.
-
C
Create IOCs of the malicious files you have found to prevent their execution.
-
D
Enable Behavioral Threat Protection (BTP) with cytool to prevent the attack from spreading.
Reveal answer details
Close answer details
Correct answerA
ExplanationTo ensure that the same protection is extended to all your servers, you need to create Behavioral Threat Protection (BTP) rules to recognize and prevent the activity. BTP is a feature of Cortex XDR that allows you to create custom rules that detect and block malicious or suspicious behaviors on your endpoints, such as file execution, process injection, network connection, or registry modification. BTP rules can use various operators, functions, and variables to define the criteria and the actions for the rules. By creating BTP rules that match the behaviors of the supply chain attack, you can prevent the attack from compromising your servers 12. Let's briefly discuss the other options to provide a comprehensive explanation: B. Enable DLL Protection on all servers but there might be some false positives: This is not the correct answer. Enabling DLL Protection on all servers will not ensure that the same protection is extended to all your servers. DLL Protection is a feature of Cortex XDR that allows you to block the execution of unsigned or untrusted DLL files on your endpoints. DLL Protection can help to prevent some types of attacks that use malicious DLL files, but it may not be effective against the supply chain attack that used a Trojanized DLL file that was digitally signed by a trusted vendor. DLL Protection may also cause some false positives, as it may block some legitimate DLL files that are unsigned or untrusted 3. C. Create IOCs of the malicious files you have found to prevent their execution: This is not the correct answer. Creating IOCs of the malicious files you have found will not ensure that the same protection is extended to all your servers. IOCs are indicators of compromise that you can create to detect and respond to known threats on your endpoints, such as file hashes, registry keys, IP addresses, domain names, or full paths. IOCs can help to identify and block the malicious files that you have already discovered, but they may not be effective against the supply chain attack that used different variants of the malicious files with different hashes or names. IOCs may also become outdated, as the attackers may change or update their files to evade detection 4. D. Enable Behavioral Threat Protection (BTP) with cytool to prevent the attack from spreading: This is not the correct answer. Enabling BTP with cytool will not ensure that the same protection is extended to all your servers. BTP is a feature of Cortex XDR that allows you to create custom rules that detect and block malicious or suspicious behaviors on your endpoints, such as file execution, process injection, network connection, or registry modification. BTP rules can help to prevent the attack from spreading, but they need to be created and configured in the Cortex XDR app, not with cytool. Cytool is a command-line tool that allows you to perform various operations on the Cortex XDR agent, such as installing, uninstalling, upgrading, or troubleshooting. Cytool does not have an option to enable or configure BTP rules. In conclusion, to ensure that the same protection is extended to all your servers, you need to create BTP rules to recognize and prevent the activity. By using BTP rules, you can create custom and flexible prevention rules that match the behaviors of the supply chain attack. Behavioral Threat Protection Create a BTP Rule DLL Protection Create an IOC Rule [Cytool]
What is an example of an attack vector for ransomware?
-
A
Performing DNS queries for suspicious domains
-
B
Performing SSL Decryption on an endpoint
-
C
Phishing emails containing malicious attachments
-
D
A URL filtering feature enabled on a firewall
Reveal answer details
Close answer details
Correct answerC
ExplanationAn example of an attack vector for ransomware is phishing emails containing malicious attachments. Phishing is a technique that involves sending fraudulent emails that appear to come from a legitimate source, such as a bank, a company, or a government agency. The emails typically contain a malicious attachment, such as a PDF document, a ZIP archive, or a Microsoft Office document, that contains ransomware or a ransomware downloader. When the recipient opens or downloads the attachment, the ransomware is executed and encrypts the files or data on the victim's system. The attacker then demands a ransom for the decryption key, usually in cryptocurrency. Phishing emails are one of the most common and effective ways of delivering ransomware, as they can bypass security measures such as firewalls, antivirus software, or URL filtering. Phishing emails can also exploit the human factor, as they can trick the recipient into opening the attachment by using social engineering techniques, such as impersonating a trusted sender, creating a sense of urgency, or appealing to curiosity or greed. Phishing emails can also target specific individuals or organizations, such as executives, employees, or customers, in a technique called spear phishing, which increases the chances of success. According to various sources, phishing emails are the main vector of ransomware attacks, accounting for more than 90% of all ransomware infections 12. Some of the most notorious ransomware campaigns, such as CryptoLocker, Locky, and WannaCry, have used phishing emails as their primary delivery method 3. Therefore, it is essential to educate users on how to recognize and avoid phishing emails, as well as to implement security solutions that can detect and block malicious attachments. References Top 7 Ransomware Attack Vectors & How to Avoid Becoming a Victim - Bitsight. What Is the Main Vector of Ransomware Attacks? A Definitive Guide CryptoLocker Ransomware Information Guide and FAQ [Locky Ransomware Information, Help Guide, and FAQ] [WannaCry ransomware attack]
What kind of attacks does Cortex XDR primarily help defend against?
-
A
Network-based denial-of-service attacks
-
B
Behavioral threats, file-based malware, and exploit-based attacks
-
C
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationAnnotation: Cortex XDR is designed to protect against behavioral threats, file-based malware, and exploit-based attacks. It uses a combination of behavioral analytics and prevention techniques to identify and block these types of attacks. Option A, C, and D represent narrower categories that Cortex XDR does not solely focus on.
Question 6
Multiple choice
Which two types of exception profiles you can create in Cortex XDR? (Choose two.)
-
A
exception profiles that apply to specific endpoints
-
B
agent exception profiles that apply to specific endpoints
-
C
global exception profiles that apply to all endpoints
-
D
role-based profiles that apply to specific endpoints
Reveal answer details
Close answer details
Correct answersB, C
ExplanationCortex XDR allows you to create two types of exception profiles: agent exception profiles and global exception profiles. Agent exception profiles apply to specific endpoints that are assigned to the profile. Global exception profiles apply to all endpoints in your network. You can use exception profiles to configure different types of exceptions, such as process exceptions, support exceptions, behavioral threat protection rule exceptions, local analysis rules exceptions, advanced analysis exceptions, or digital signer exceptions. Exception profiles help you fine-tune the security policies for your endpoints and reduce false positives. References: Exception Security Profiles Create an Agent Exception Profile Create a Global Exception Profile
Which of the following is NOT a precanned script provided by Palo Alto Networks?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationPalo Alto Networks provides a set of precanned scripts that you can use to perform various actions on your endpoints, such as deleting files, killing processes, or quarantining malware. The precanned scripts are written in Python and are available in the Agent Script Library in the Cortex XDR console. You can use the precanned scripts as they are, or you can customize them to suit your needs. The precanned scripts are: delete_file: Deletes a specific file from a local or removable drive. quarantine_file: Moves a specific file from its location on a local or removable drive to a protected folder and prevents it from being executed. process_kill_name: Kills a process by its name on the endpoint. process_kill_pid: Kills a process by its process ID (PID) on the endpoint. process_kill_tree: Kills a process and all its child processes by its name on the endpoint. process_kill_tree_pid: Kills a process and all its child processes by its PID on the endpoint. process_list: Lists all the processes running on the endpoint, along with their names, PIDs, and command lines. process_list_tree: Lists all the processes running on the endpoint, along with their names, PIDs, command lines, and parent processes. process_start: Starts a process on the endpoint by its name or path. registry_delete_key: Deletes a registry key and all its subkeys and values from the Windows registry. registry_delete_value: Deletes a registry value from the Windows registry. registry_list_key: Lists all the subkeys and values under a registry key in the Windows registry. registry_list_value: Lists the value and data of a registry value in the Windows registry. registry_set_value: Sets the value and data of a registry value in the Windows registry. The script list_directories is not a precanned script provided by Palo Alto Networks. It is a custom script that you can write yourself using Python commands. Run Scripts on an Endpoint Agent Script Library Precanned Scripts
When investigating security events, which feature in Cortex XDR is useful for reverting the changes on the endpoint?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationWhen investigating security events, the feature in Cortex XDR that is useful for reverting the changes on the endpoint is Remediation Suggestions. Remediation Suggestions are a feature of Cortex XDR that provide you with recommended actions to undo the effects of malicious activity on your endpoints. You can view the remediation suggestions for each alert or incident in the Cortex XDR console, and decide whether to apply them or not. Remediation Suggestions can help you restore the endpoint to its original state, remove malicious files or processes, or fix registry or system settings. Remediation Suggestions are based on the forensic data collected by the Cortex XDR agent and the analysis performed by Cortex XDR. References Remediation Suggestions Apply Remediation Suggestions
Which of the following features is primarily used to manage agent updates in Cortex XDR?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationAgent Installations is the feature in Cortex XDR used for managing agent updates, including the installation and upgrade of agents across endpoints. Option B, while it provides visibility into asset data, does not focus on managing agent updates. Options C and D are unrelated.
Question 10
Single choice
How does Cortex XDR agent for Windows prevent ransomware attacks from compromising the file system?
-
A
by encrypting the disk first.
-
B
by utilizing decoy Files.
-
C
by retrieving the encryption key.
-
D
by patching vulnerable applications.
Reveal answer details
Close answer details
Correct answerB
ExplanationCortex XDR agent for Windows prevents ransomware attacks from compromising the file system by utilizing decoy files. Decoy files are randomly generated files that are placed in strategic locations on the endpoint, such as the user's desktop, documents, and pictures folders. These files are designed to look like valuable data that ransomware would target for encryption. When Cortex XDR agent detects that a process is attempting to access or modify a decoy file, it immediately blocks the process and alerts the administrator. This way, Cortex XDR agent can stop ransomware attacks before they can cause any damage to the real files on the endpoint. References: Anti-Ransomware Protection PCDRA Study Guide
Question 11
Single choice
In the Cortex XDR console, which of the following actions can be performed on an isolated endpoint?
-
A
-
B
Initiate a remediation suggestion
-
C
Perform a full system restore
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationIn the Cortex XDR console, you can initiate remediation suggestions for isolated endpoints to automatically fix issues like removing malicious files or restoring system configurations. Option A and C are not effective or feasible actions directly from the console in isolation, while D is not a standard tool for this scenario. Correct Answers:
Question 12
Single choice
When using the "File Search and Destroy" feature, which of the following search hash type is supported?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationThe File Search and Destroy feature is a capability of Cortex XDR that allows you to search for and delete malicious or unwanted files across your endpoints. You can use this feature to quickly respond to incidents, remediate threats, and enforce compliance policies. To use the File Search and Destroy feature, you need to specify the file name and the file hash of the file you want to search for and delete. The file hash is a unique identifier of the file that is generated by a cryptographic hash function. The file hash ensures that you are targeting the exact file you want, and not a file with a similar name or a different version. The File Search and Destroy feature supports the SHA256 hash type, which is a secure hash algorithm that produces a 256-bit (32-byte) hash value. The SHA256 hash type is widely used for file integrity verification and digital signatures. The File Search and Destroy feature does not support other hash types, such as AES256, MD5, or SHA1, which are either encryption algorithms or less secure hash algorithms. Therefore, the correct answer is A, SHA256 hash of the file1234 File Search and Destroy What is a File Hash? SHA-2 - Wikipedia When using the "File Search and Destroy" feature, which of the following search hash type is supported?
Question 13
Single choice
What is the Wildfire analysis file size limit for Windows PE files?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationThe Wildfire analysis file size limit for Windows PE files is 100MB. Windows PE files are executable files that run on the Windows operating system, such as.exe,.dll,.sys, or.scr files. Wildfire is a cloud-based service that analyzes files and URLs for malicious behavior and generates signatures and protections for them. Wildfire can analyze various file types, such as PE, APK, PDF, MS Office, and others, but each file type has a different file size limit. The file size limit determines the maximum size of the file that can be uploaded or forwarded to Wildfire for analysis. If the file size exceeds the limit, Wildfire will not analyze the file and will return an error message. According to the Wildfire documentation1, the file size limit for Windows PE files is 100MB. This means that any PE file that is larger than 100MB will not be analyzed by Wildfire. However, the firewall can still apply other security features, such as antivirus, anti-spyware, vulnerability protection, and file blocking, to the PE file based on the security policy settings. The firewall can also perform local analysis on the PE file using the Cortex XDR agent, which uses machine learning models to assess the file and assign it a verdict 2. WildFire File Size Limits: This document provides the file size limits for different file types that can be analyzed by Wildfire. Local Analysis: This document explains how the Cortex XDR agent performs local analysis on files that cannot be sent to Wildfire for analysis.
Question 14
Single choice
What contains a logical schema in an XQL query?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationA logical schema in an XQL query is a field, which is a named attribute of a dataset. A field can have a data type, such as string, integer, boolean, or array. A field can also have a modifier, such as bin or expand, that transforms the field value in the query output. A field can be used in the select, where, group by, order by, or having clauses of an XQL query. References XQL Syntax XQL Data Types XQL Field Modifiers
Question 15
Single choice
Which of the following policy exceptions applies to the following description? 'An exception allowing specific PHP files'
-
A
-
B
Local file threat examination exception
-
C
Behavioral threat protection rule exception
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationThe policy exception that applies to the following description is B, local file threat examination exception. A local file threat examination exception is an exception that allows you to exclude specific files or folders from being scanned by the Cortex XDR agent for malware or threats. You can use this exception to prevent false positives, performance issues, or compatibility problems with legitimate files or applications. You can define the local file threat examination exception by file name, file path, file hash, or digital signer. For example, you can create a local file threat examination exception for specific PHP files by entering their file names or paths in the exception configuration. References Local File Threat Examination Exceptions Create a Local File Threat Examination Exception
Question 16
Single choice
Which Type of IOC can you define in Cortex XDR?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationCortex XDR allows you to define IOCs based on various criteria, such as file hashes, registry keys, IP addresses, domain names, and full paths. A full path IOC is a specific location of a file or folder on an endpoint, such as C:\Windows \System32\calc.exe. You can use full path IOCs to detect and respond to malicious files or folders that are located in known locations on your endpoints 12. Let's briefly discuss the other options to provide a comprehensive explanation: A. destination port: This is not the correct answer. Destination port is not a type of IOC that you can define in Cortex XDR. Destination port is a network attribute that indicates the port number to which a packet is sent. Cortex XDR does not support defining IOCs based on destination ports, but you can use XQL queries to filter network events by destination ports 3. B. e-mail address: This is not the correct answer. E-mail address is not a type of IOC that you can define in Cortex XDR. E-mail address is an identifier that is used to send and receive e-mails. Cortex XDR does not support defining IOCs based on e-mail addresses, but you can use the Cortex XDR - IOC integration with Cortex XSOAR to ingest IOCs from various sources, including e-mail addresses 4. D. App-ID: This is not the correct answer. App-ID is not a type of IOC that you can define in Cortex XDR. App-ID is a feature of Palo Alto Networks firewalls that identifies and controls applications on the network. Cortex XDR does not support defining IOCs based on App-IDs, but you can use the Cortex XDR Analytics app to create custom rules that use App-IDs as part of the rule logic 5. In conclusion, full path is the type of IOC that you can define in Cortex XDR. By using full path IOCs, you can enhance your detection and response capabilities and protect your endpoints from malicious files or folders. Create an IOC Rule XQL Reference Guide: Network Events Schema Cortex XDR - IOC Cortex XDR Analytics App PCDRA: Which Type of IOC can define in Cortex XDR?
Question 17
Single choice
A Linux endpoint with a Cortex XDR Pro per Endpoint license and Enhanced Endpoint Data enabled has reported malicious activity, resulting in the creation of a file that you wish to delete. Which action could you take to delete the file?
-
A
Manually remediate the problem on the endpoint in question.
-
B
Open X2go from the Cortex XDR console and delete the file via X2go.
-
C
Initiate Remediate Suggestions to automatically delete the file.
-
D
Open an NFS connection from the Cortex XDR console and delete the file.
Reveal answer details
Close answer details
Correct answerC
ExplanationThe best action to delete the file on the Linux endpoint is to initiate Remediation Suggestions from the Cortex XDR console. Remediation Suggestions are a feature of Cortex XDR that provide you with recommended actions to undo the effects of malicious activity on your endpoints. You can view the remediation suggestions for each alert or incident in the Cortex XDR console, and decide whether to apply them or not. Remediation Suggestions can help you restore the endpoint to its original state, remove malicious files or processes, or fix registry or system settings. Remediation Suggestions are based on the forensic data collected by the Cortex XDR agent and the analysis performed by Cortex XDR. The other options are incorrect for the following reasons: A is incorrect because manually remediating the problem on the endpoint is not a convenient or efficient way to delete the file. Manually remediating the problem would require you to access the endpoint directly, log in as root, locate the file, and delete it. This would also require you to have the necessary permissions and credentials to access the endpoint, and to know the exact path and name of the file. Manually remediating the problem would also not provide you with any audit trail or confirmation of the deletion. B is incorrect because opening X2go from the Cortex XDR console is not a supported or secure way to delete the file. X2go is a third-party remote desktop software that allows you to access Linux endpoints from a graphical user interface. However, X2go is not integrated with Cortex XDR, and using it would require you to install and configure it on both the Cortex XDR console and the endpoint. Using X2go would also expose the endpoint to potential network attacks or unauthorized access, and would not provide you with any audit trail or confirmation of the deletion. D is incorrect because opening an NFS connection from the Cortex XDR console is not a feasible or reliable way to delete the file. NFS is a network file system protocol that allows you to access files on remote servers as if they were local. However, NFS is not integrated with Cortex XDR, and using it would require you to set up and maintain an NFS server and client on both the Cortex XDR console and the endpoint. Using NFS would also depend on the network availability and performance, and would not provide you with any audit trail or confirmation of the deletion. Remediation Suggestions Apply Remediation Suggestions
|