Question 71

A critical server in your environment is suspected of being compromised. You observe unusual outbound connections to a public cloud IP range not typically used by your organization. However, the connections are to common ports (e.g., 443, 80). Cortex XDR has not flagged these as malicious, but your threat intelligence suggests this IP range has recently been associated with command and control (C2) infrastructure. You need to leverage Cortex XDR to confirm the C2, identify the associated process, and understand the data exfiltration attempt. Which of the following Cortex XDR capabilities would you utilize in conjunction to effectively hunt for and confirm this sophisticated C2 activity, even if it's currently evading standard detections?
  • Question 72

    A security incident involving a suspected insider threat is being investigated. The incident response lead wants to ensure that all actions taken within the War Room are transparent, auditable, and attributable to specific team members. Furthermore, sensitive information shared (e.g., internal IP addresses, employee IDs) must be handled securely within the War Room environment. How does Cortex XSOAR's War Room inherently address these requirements, and what features contribute to this?
  • Question 73

    During a red team exercise, an attacker successfully bypassed the organization's EDR by exploiting a zero-day vulnerability in a popular browser, then used an undocumented technique to perform process hollowing and inject shellcode into a legitimate system process. The EDR, relying on known signatures and common behavioral patterns, missed this highly evasive attack. Which specific characteristic of Cortex XDR's detection engine, as part of its 'Prevention First' approach, would have been most likely to detect and prevent such an advanced, evasive threat, even without a prior signature?
  • Question 74

    A global financial institution uses Cortex XSIAM to monitor its highly regulated environment. They have a strict policy that no agents can be installed on certain legacy critical production servers due to vendor support agreements. However, network-level visibility for these servers is still required for compliance and threat detection. Furthermore, the institution heavily relies on Microsoft 365 for collaboration and email. Which Cortex XSIAM sensor types would be best suited to address these specific requirements, and what data would they ingest?
  • Question 75

    An organization relies heavily on Palo Alto Networks Cortex XSOAR for security orchestration, automation, and response. A major incident involving ransomware has encrypted critical data across multiple departments. During the eradication phase, the incident response team needs to deploy a custom script to remove persistence mechanisms left by the ransomware and distribute a decryption tool. This script needs to run on hundreds of affected endpoints. Which XSOAR playbook command or integration would be most suitable and efficient for this task, ensuring proper execution and feedback?