Question 41

A Security Operations Center (SOC) analyst is investigating a series of alerts generated by Cortex XDR's Behavioral Analytics engine. The alerts indicate unusual network traffic patterns originating from several internal workstations, all communicating with an unregistered external IP address on a non-standard port. No known signatures or IOCs are associated with this activity. Which key element of Cortex XDR's behavioral analytics is most likely responsible for detecting this anomaly, and how does it achieve this?
  • Question 42

    A recent audit revealed that some XSOAR playbooks are performing redundant API calls to a highly rate-limited external service. The team wants to implement a global caching mechanism for this specific service's responses. They decide to use a custom cache where data is stored for 15 minutes. This cache needs to be accessible by multiple playbooks and their embedded scripts. Which of the following approaches is the MOST scalable and maintainable for implementing this shared, time-based caching in XSOAR, considering the distinction between Scripts and Jobs?
  • Question 43

    During a malware outbreak investigation, Cortex XDR has identified a novel executable ('malware.exe') spreading rapidly across several Windows endpoints. The Security Analyst needs to understand the execution chain, parent-child relationships, and network beaconing associated with this artifact. Which specific data sources within Cortex XDR are paramount for constructing a comprehensive forensic timeline of 'malware.exe' activity?
  • Question 44

    Your organization uses a custom internal application for managing critical assets, which lacks a direct XSOAR integration. A new XSOAR playbook needs to update the status of an asset in this custom application based on incident remediation actions. The custom application exposes a REST API for status updates, requiring a specific JSON payload. Which two XSOAR features or methods are most appropriate for securely and dynamically interacting with this custom REST API within the playbook?
  • Question 45

    During a highly sensitive investigation, the incident response team determines that an attacker is attempting to exfiltrate compressed, encrypted intellectual property via DNS tunneling through multiple legitimate-looking subdomains of a compromised public domain. The Palo Alto Networks NGFW, with Advanced Threat Prevention and DNS Security subscriptions, is in place. Which specific configurations and features would be leveraged to detect and prevent this advanced exfiltration technique, prioritizing accuracy and minimizing false positives?