CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 26: PSE-CORTEX: Palo Alto Networks System Engineer Professional - Cortex

Cortex XSOAR has extracted a malicious Internet Protocol (IP) address involved in command-and-control (C2) traffic. What is the best method to block this IP from communicating with endpoints without requiring a configuration change on the firewall?

Nội dung câu hỏi

Cortex XSOAR has extracted a malicious Internet Protocol (IP) address involved in command-and-control (C2) traffic. What is the best method to block this IP from communicating with endpoints without requiring a configuration change on the firewall?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Have XSOAR automatically add the IP address to a threat intelligence management (TIM) malicious IP list to elevate priority of future alerts.
  2. B. Have XSOAR automatically add the IP address to a deny rule in the firewall.
  3. C. Have XSOAR automatically add the IP address to an external dynamic list (EDL) used by the firewall. — đáp án hiện tại
  4. D. Have XSOAR automatically create a NetOps ticket requesting a configuration change to the firewall to block the IP.

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề