XSIAM-Analyst Exam Question 16

During an investigation, an analyst runs the reputation script for an indicator that is listed as Suspicious. The new reputation results display in the War Room as Malicious; however, the indicator verdict does not change.
What is the cause of this behavior?
  • XSIAM-Analyst Exam Question 17

    Which Cortex XSIAM feature displays the latest agent health and connection status?
    Response:
  • XSIAM-Analyst Exam Question 18

    You notice certain threat types are under-prioritized. What two customizations can address this?
    Response:
  • XSIAM-Analyst Exam Question 19

    SCENARIO:
    A security analyst has been assigned a ticket from the help desk stating that users are experiencing errors when attempting to open files on a specific network share. These errors state that the file format cannot be opened. IT has verified that the file server is online and functioning, but that all files have unusual extensions attached to them.
    The security analyst reviews alerts within Cortex XSIAM and identifies malicious activity related to a possible ransomware attack on the file server. This incident is then escalated to the incident response team for further investigation.
    Upon reviewing the incident, the responders confirm that ransomware was successfully executed on the file server. Other details of the attack are noted below:
    * An unpatched vulnerability on an externally facing web server was exploited for initial access
    * The attackers successfully used Mimikatz to dump sensitive credentials that were used for privilege escalation
    * PowerShell was used on a Windows server for additional discovery, as well as lateral movement to other systems
    * The attackers executed SystemBC RAT on multiple systems to maintain remote access
    * Ransomware payload was downloaded on the file server via an external site "file io" QUESTION STATEMENT:
    The incident responders are attempting to determine why Mimikatz was able to successfully run during the attack.
    Which exploit protection profile in Cortex XSIAM should be reviewed to ensure it is configured with an Action Mode of Block?
  • XSIAM-Analyst Exam Question 20

    A security analyst is reviewing alerts and incidents associated with internal vulnerability scanning performed by the security operations team.
    Which built-in incident domain will be assigned to these alerts and incidents in Cortex XSIAM?