PSE-Cortex Exam QuestionsBrowse all questions from this exam

PSE-Cortex Exam - Question 4


Cortex XSOAR has extracted a malicious Internet Protocol (IP) address involved in command-and-control (C2) traffic.

What is the best method to block this IP from communicating with endpoints without requiring a configuration change on the firewall?

Show Answer
Correct Answer: C

The best method to block an IP address involved in command-and-control (C2) traffic without requiring a configuration change on the firewall is to have XSOAR automatically add the IP address to an external dynamic list (EDL) used by the firewall. EDLs are lists that can be dynamically updated and referenced by firewall policies to block or allow traffic. This method allows the firewall to automatically update its blocking rules based on the latest threat intelligence without needing manual configuration changes.

Discussion

1 comment
Sign in to comment
5688ac9Option: C
Jul 12, 2024

C is correct