Exam PCDRA All QuestionsBrowse all questions from this exam
Question 4

What are two purposes of “Respond to Malicious Causality Chains” in a Cortex XDR Windows Malware profile? (Choose two.)

    Correct Answer: A, B

    In a Cortex XDR Windows Malware profile, 'Respond to Malicious Causality Chains' serves two key purposes. First, it can automatically close the connections involved in malicious traffic, thereby halting any ongoing malicious communication. Second, it has the capability to automatically kill the processes that are involved in the malicious activity, effectively stopping the malicious behavior at its source. These actions are crucial for neutralizing threats and preventing further damage to the system.

Discussion
KarreldanamOptions: AD

(Windows only) Respond to Malicious Causality Chains. When the Cortex XDR agent identifies a remote network connection that attempts to perform malicious activity—such as encrypting endpoint files—the agent can automatically block the IP address to close all existing communication and block new connections from this IP address to the endpoint. When Cortex XDRblocks an IP address per endpoint, that address remains blocked throughout all agent profiles and policies, including any host-firewall policy rules. You can view the list of all blocked IP addresses per endpoint from the Action Center, as well as unblock them to re-enable communication as appropriate.

news088Options: AD

selected answer AD https://live.paloaltonetworks.com/t5/community-blogs/cortex-xdr-agent-7-3-new-features/ba-p/383329

sharkk43Options: AD

I say it's A and D because of what I'm just reading off the official course in the section "Respond to Malicious Causality Chains". It goes like this: "When the Cortex XDR agent detects a malicious activity, the Respond to Malicious Causality Chains module inspects the network connections opened by the processes involved in the attack to identify malicious IP addresses." To me that's A nd D not A and C.

sharkk43

Forgot to add the second part: "If such network connections are found, this protection module can automatically close all the network connections and block new connection requests from these IP addresses."

unns12Options: CD

CD is correct

XuannnnOAOOptions: CD

CD is correct