QuestionQ20

Cortex XDR Agent Configuration

How can a Malware profile be configured to stop a specific executable from being uploaded to the cloud?

  • A Add the executable to the allow list for executions.
  • B Disable on-demand file examination for the executable.
  • C Create an exclusion rule for the executable.
  • D Set PE and DLL examination for the executable to report action mode.
Explanation

An exclusion rule removes the specified executable from malware analysis and cloud submission. Execution allow lists, on-demand examination settings, and report-only PE/DLL examination do not prevent that executable from being uploaded to the cloud.

Community Discussion

No comments yet. Be the first to start the discussion!