QuestionQ107
Cortex XDRAn analyst is investigating a critical incident on a Windows server where malware execution resulted in numerous file deletions and registry-key changes. The affected files and registry keys must be restored efficiently and quickly.
Which Cortex XDR response action should the analyst choose?
- A Execute the Isolate Endpoint action, which automatically reverses all known malware-related changes upon successful isolation.
- B Run the Search and Destroy action on all affected endpoints to automatically replace all files with a “good” hash from the content update package.
- C Initiate a Live Terminal session and use operating system commands to manually copy original files from a network share and import a clean registry hive.
- D Use the Remediation Suggestions action to review and apply the recommended actions for restoring the files and registry values.
Community Discussion