QuestionQ1

Cortex Fundamentals

A threat-intelligence team determines that IP addresses associated with brute-force attacks against the VPN gateways have historical links to a ransomware campaign.

Which two Cortex features can be configured to trigger alerts for malicious objects and for specified system processes associated with the threat actors’ tactics, techniques, and procedures (TTPs)?

Choose two
  • A External dynamic list
  • B Security event anomaly
  • C Behavioral indicator of compromise (BIOC)
  • D Indicator of compromise (IOC)
Explanation

Cortex IOC rules generate alerts for known malicious or suspicious static artifacts, such as IP addresses, domains, file hashes, filenames, and paths. BIOC rules detect suspicious behavior involving processes, files, registry activity, and network activity, so they can identify system-process behavior associated with adversary TTPs.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!