CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 11: SecOps-Pro: Palo Alto Networks Security Operations Professional

Which action should an administrator take to create automated response actions when a user account is compromised, allowing attacker to upload data to an external IP address and infect a machine on the company network with malware?

Nội dung câu hỏi

Which action should an administrator take to create automated response actions when a user account is compromised, allowing attacker to upload data to an external IP address and infect a machine on the company network with malware?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Create automation rules in Cortex XDR that will trigger for each alert.
  2. B. Create a script in Cortex XSOAR that will run a playbook based on the scenario.
  3. C. Create playbook triggers in Cortex XSIAM and run playbooks for each alert. — đáp án hiện tại
  4. D. Map the events as type of Cortex XSOAR incident, then run a playbook.

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề