Câu 5: XSIAM-ANALYST: Palo Alto Networks Certified XSIAM Analyst
A Cortex XSIAM analyst is investigating a security incident involving a workstation after having deployed a Cortex XDR agent for 45 days. The incident details include the Cortex XDR Analytics Alert "Uncommon remote scheduled task creation."Which response will mitigate the threat?
Nội dung câu hỏi
A Cortex XSIAM analyst is investigating a security incident involving a workstation after having deployed a Cortex XDR agent for 45 days. The incident details include the Cortex XDR Analytics Alert "Uncommon remote scheduled task creation."Which response will mitigate the threat?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. Revoke user access and conduct a user audit.
- B. Allow list the processes to reduce alert noise.
- C. Initiate the endpoint isolate action to contain the threat. — đáp án hiện tại
- D. Prioritize blocking the source IP address to prevent further login attempts.
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.
Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.