Weekend Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Exam XDR-Engineer All Questions
Exam XDR-Engineer All Questions

View all questions & answers for the XDR-Engineer exam

Paloalto Networks Security Operations XDR-Engineer Question # 6 Topic 1 Discussion

XDR-Engineer Exam Topic 1 Question 6 Discussion:
Question #: 6
Topic #: 1

A security audit determines that the Windows Cortex XDR host-based firewall is not blocking outbound RDP connections for certain remote workers. The audit report confirms the following:

    All devices are running healthy Cortex XDR agents.

    A single host-based firewall rule to block all outbound RDP is implemented.

    The policy hosting the profile containing the rule applies to all Windows endpoints.

    The logic within the firewall rule is adequate.

    Further testing concludes RDP is successfully being blocked on all devices tested at company HQ.

    Network location configuration in Agent Settings is enabled on all Windows endpoints.What is the likely reason the RDP connections are not being blocked?


A.

The profile's default action for outbound traffic is set to Allow


B.

The pertinent host-based firewall rule group is only applied to external rule groups


C.

Report mode is set to Enabled in the report settings under the profile configuration


D.

The pertinent host-based firewall rule group is only applied to internal rule groups


Get Premium XDR-Engineer Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.