During inspection of your Threat Prevention logs you find four different computers having one event each with a Critical Severity. Which of those hosts should you try to remediate first?
A.
Host having a Critical event found by Threat Emulation
B.
Host having a Critical event found by IPS
C.
Host having a Critical event found by Antivirus
I think answer is D because Anti-Bot is detecting communication from already infected hosts to Control Centers in internet. It is not preventive issue, its like issue after infection take place.
D, since Anti-Bot indicates that an endpoint is attempting to connect to a malicious C&C IP; thus indicating it is already infected
upvoted 1 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Nikolas
Highly Voted 1 year, 8 months agolordlich
Most Recent 6 months, 1 week agoFriedExams
6 months, 1 week ago