QuestionQ10

Maintenance and Troubleshooting

A security audit finds that the Windows Cortex XDR host-based firewall is not blocking outbound RDP connections for some remote workers. The audit report confirms the following:

  • All devices run healthy Cortex XDR agents.
  • One host-based firewall rule is implemented to block all outbound RDP.
  • The policy that hosts the profile containing the rule applies to every Windows endpoint.
  • The firewall rule logic is adequate.
  • Further testing confirms that RDP is successfully blocked on all devices tested at company HQ.
  • Network location configuration in Agent Settings is enabled on all Windows endpoints.

What is the likely reason that the RDP connections are not being blocked?

  • A The pertinent host-based firewall rule group is only applied to external rule groups.
  • B Report mode is set to Enabled in the report settings under the profile configuration.
  • C The pertinent host-based firewall rule group is only applied to internal rule groups.
  • D The profile’s default action for outbound traffic is set to Allow.
Explanation

When network-location configuration is enabled, host-based firewall rule groups can be applied separately to internal and external locations. A block that succeeds at headquarters but not for remote workers is scoped only to internal rule groups, so it is not enforced while those endpoints are external.

Community Discussion

No comments yet. Be the first to start the discussion!