Question 1
Q1A SOC analyst at a financial services firm is investigating a high-severity incident originating from a database server. The causality chain indicates that a legitimate, signed administrative tool, db_admin_util.exe, was used to spawn a PowerShell process that connected to a known malicious IP address. The firm's policy prohibits isolating this critical server. Which response action in Cortex XDR would be most effective at containing the immediate threat while adhering to the policy?
Show answer & explanation
Correct answer: B
Terminating the specific malicious process is the most precise action. It stops the active threat (the C2 connection) without disrupting the legitimate administrative tool or the server's primary function, thus adhering to the policy against isolation. Blocking the legitimate tool's hash would cause operational disruption. Isolating the host is explicitly forbidden. Adding the IP to a block list is a good secondary step but doesn't stop the already running process.