Câu 26: PSE-CORTEX: Palo Alto Networks System Engineer Professional - Cortex
Cortex XSOAR has extracted a malicious Internet Protocol (IP) address involved in command-and-control (C2) traffic. What is the best method to block this IP from communicating with endpoints without requiring a configuration change on the firewall?
Nội dung câu hỏi
Cortex XSOAR has extracted a malicious Internet Protocol (IP) address involved in command-and-control (C2) traffic. What is the best method to block this IP from communicating with endpoints without requiring a configuration change on the firewall?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. Have XSOAR automatically add the IP address to a threat intelligence management (TIM) malicious IP list to elevate priority of future alerts.
- B. Have XSOAR automatically add the IP address to a deny rule in the firewall.
- C. Have XSOAR automatically add the IP address to an external dynamic list (EDL) used by the firewall. — đáp án hiện tại
- D. Have XSOAR automatically create a NetOps ticket requesting a configuration change to the firewall to block the IP.
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.
Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.