Câu 11: SecOps-Pro: Palo Alto Networks Security Operations Professional
Which action should an administrator take to create automated response actions when a user account is compromised, allowing attacker to upload data to an external IP address and infect a machine on the company network with malware?
Nội dung câu hỏi
Which action should an administrator take to create automated response actions when a user account is compromised, allowing attacker to upload data to an external IP address and infect a machine on the company network with malware?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. Create automation rules in Cortex XDR that will trigger for each alert.
- B. Create a script in Cortex XSOAR that will run a playbook based on the scenario.
- C. Create playbook triggers in Cortex XSIAM and run playbooks for each alert. — đáp án hiện tại
- D. Map the events as type of Cortex XSOAR incident, then run a playbook.
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.
Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.