Question 81

Consider the following Cortex XDR KQL query used by a security analyst:

This query is attempting to identify instances of PowerShell being used for credential dumping. From a behavioral analytics perspective, what is the primary limitation of relying solely on such a KQL query for detecting advanced persistent threats (APTs) that often leverage living-off-the-land (LOTL) techniques?
  • Question 82

    Your organization uses a highly integrated Palo Alto Networks security ecosystem, including NG Firewalls, Cortex XDR, and Cortex XSOAR. An active phishing campaign is targeting your employees, using a novel social engineering technique to bypass initial email security layers. Threat intelligence indicates the campaign uses a specific, newly registered domain ('malicious-phish.xyz') and downloads a custom payload with a unique MD5 hash ('al b2c3d4e5f6g7h8i9j0k112m3n405p6'). Which of the following automated,workflows in Cortex XSOAR, triggered by threat intelligence, would provide the most comprehensive and rapid response to contain and eradicate this threat, and enrich future intelligence?
  • Question 83

    A sophisticated email-based attack bypasses initial defenses and delivers a malicious payload. The incident is triggered in Cortex XSOAR. The playbook is designed to: 1. Extract all email headers and body content. 2. Detonate any suspicious attachments in a sandbox. 3. Extract all URLs and file hashes from the email and sandbox results. 4. Query multiple external threat intelligence feeds (e.g., VirusTotal, AlienVault OT X) for these IOCs. 5. If any IOC is confirmed malicious, block the sender's email address on the email security gateway, block the malicious URLs on the proxy, and quarantine the original email from all inboxes. If the playbook encounters an attachment type that the sandbox integration does not support, and consequently, no hashes are extracted for that specific attachment, but other parts of the email and other attachments are successfully processed and detonated, which of the following best describes the desired XSOAR playbook design to handle this specific partial failure gracefully and continue the investigation?
  • Question 84

    A large enterprise is onboarding its AWS CloudTrail logs into Cortex XSIAM. They have multiple AWS accounts, and the CloudTrail logs are delivered to separate S3 buckets in different regions. The security team needs to ensure all audit logs are ingested efficiently, parsed correctly, and enriched with account IDs and region information for granular security analytics and compliance reporting. Which of the following ingestion strategies within Cortex XSIAM is the most scalable and robust for this scenario, and what specific configurations would be required?
  • Question 85

    A mid-sized e-commerce company is struggling with rapid incident response for credential theft attacks. Their current EDR provides good endpoint visibility, but when an attacker successfully compromises a user account, lateral movement and access to cloud resources often go undetected until significant damage is done. The security team needs a solution that can automatically detect and respond to suspicious activities spanning endpoints and cloud identity providers. Which Cortex XDR feature is most relevant here?