Question 11

A sophisticated zero-day attack has compromised several critical servers. The incident response team is using Cortex XSOAR's War Room. Due to the novelty of the attack, existing automated playbooks are insufficient for complete remediation. The team needs to collaboratively develop and test new detection and response logic, share custom scripts, and validate their effectiveness in a live, yet controlled, environment within the War Room. How does the War Room facilitate this agile, iterative development and testing process during a live incident?
  • Question 12

    A critical server environment is configured with Cortex XDR in a 'Detect Only' mode for its Behavioral Threat Protection policy due to application compatibility concerns, but WildFire submissions are enabled. An unknown, highly obfuscated PowerShell script attempts to establish a persistent backdoor using WMI and then beacon to a C2 server via DNS tunneling. While XDR does not prevent this in 'Detect Only' mode, how would WildFire contribute to the overall security posture and incident response in this specific scenario?
  • Question 13

    A new variant of ransomware has bypassed traditional signature-based antivirus on a client's endpoint. Cortex XDR, however, successfully prevented the encryption of critical files and isolated the endpoint. Upon investigation, it was determined that the ransomware attempted to enumerate shadow copies, delete volume shadow copies, and then encrypt files with a specific extension. Which two key behavioral analytics capabilities of Cortex XDR were most crucial in identifying and stopping this zero-day ransomware attack?
  • Question 14

    Consider a scenario where a custom, fileless malware variant attempts to inject malicious code into a legitimate process's memory space and then execute it. The malware completely bypasses disk-based detection mechanisms. Which Cortex XDR sensor capabilities are most critical for detecting and preventing this type of attack, and why?
  • Question 15

    A Security Operations Center (SOC) analyst is investigating a suspected lateral movement incident. Cortex XDR has triggered an alert indicating suspicious PowerShell activity originating from a compromised endpoint. The analyst needs to rapidly understand the scope of compromise, specifically identifying other systems the attacker may have accessed using stolen credentials. Which key Cortex XDR elements, in combination, would be most crucial for efficiently tracing the attacker's path and identifying affected assets?