View all questions & answers for the PSE-Cortex exam
Cortex XSOAR has extracted a malicious IP address involved in command-and-control traffic.
What is the best method to automatically block this IP from communicating with endpoints without requiring a configuration change on the firewall?
Create a NetOps ticket requesting a configuration change to the firewall to block the IP.
Add the IP address to an external dynamic list used by the firewall.
Add the IP address to a threat intelligence management malicious IP list to elevate priority of future alerts.
Block the IP address by creating a deny rule in the firewall.
Submit