An Incident Responder notices traffic going from an endpoint to an IRC channel. The endpoint is listed in an incident. ATP is configured in TAP mode.
What should the Incident Responder do to stop the traffic to the IRC channel?
정답:
Question No : 3
Which threat is an example of an Advanced Persistent Threat (APT)?
정답:
Question No : 4
Which two tasks should an Incident Responder complete when recovering from an incident? (Choose two.)
정답:
Question No : 5
What occurs when an endpoint fails its Host Integrity check and is unable to remediate?
정답:
Question No : 6
What is the earliest stage at which a SQL injection occurs during an Advanced Persistent Threat (APT) attack?
정답:
Question No : 7
An Incident Responder wants to investigate whether msscrt.pdf resides on any systems.
Which search query and type should the responder run?
정답:
Question No : 8
Where can an Incident Responder view Cynic results in ATP?
How should an ATP Administrator configure Endpoint Detection and Response according to Symantec best practices for a SEP environment with more than one domain?