Exam PCDRA All QuestionsBrowse all questions from this exam
Question 40

Which of the following protection modules is checked first in the Cortex XDR Windows agent malware protection flow?

    Correct Answer: D

    The first protection module checked in the Cortex XDR Windows agent malware protection flow is the Child Process Protection. When a process attempts to launch any child processes, the Cortex XDR agent first evaluates the child process protection policy. If the parent process is a known targeted process attempting to launch a restricted child process, the Cortex XDR agent blocks the child processes from running and reports the security event.

Discussion
SpTesterOption: D

Phase 1: Evaluation of Child Process Protection Policy When a user attempts to run an executable, the operating system attempts to run the executable as a process. If the process tries to launch any child processes, the Cortex XDR agent first evaluates the child process protection policy. If the parent process is a known targeted process that attempts to launch a restricted child process, the Cortex XDR agent blocks the child processes from running and reports the security event to Cortex XDR.

escarOption: D

should be - Evaluation of Child Process Protection Policy https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/File-Analysis-and-Protection-Flow

ChiquitabanditaOption: D

saw this in admin guide https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/File-Analysis-and-Protection-Flow

darylmaeb24Option: D

D is the correct answer

examlogOption: D

Correct Answer D. Child Process Protection https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/File-Analysis-and-Protection-Flow If the process tries to launch any child processes, the Cortex XDR agent first evaluates the child process protection policy. If the parent process is a known targeted process that attempts to launch a restricted child process, the Cortex XDR agent blocks the child processes from running and reports the security event to Cortex XDR.

Davina07Option: D

See link from escar