QuestionQ1
Cortex FundamentalsA threat-intelligence team determines that IP addresses associated with brute-force attacks against the VPN gateways have historical links to a ransomware campaign.
Which two Cortex features can be configured to trigger alerts for malicious objects and for specified system processes associated with the threat actors’ tactics, techniques, and procedures (TTPs)?
Choose two
- A External dynamic list
- B Security event anomaly
- C Behavioral indicator of compromise (BIOC)
- D Indicator of compromise (IOC)
Community Discussion