Which action should an Incident Responder take to remediate false positives, according to Symantec best practices?
A) Blacklist
B) Whitelist
C) Delete file
D) Submit file to Cynic
Correct Answer:
Verified
Q68: An Incident Responder observes an incident with
Q69: What occurs when an endpoint fails its
Q70: Which prerequisite is necessary to extend the
Q71: An Incident Responder wants to investigate whether
Q72: How can an Incident Responder generate events
Q74: Which two tasks should an Incident Responder
Q75: Which threat is an example of an
Q76: Which threat is an example of an
Q77: What does a Quarantine Firewall policy enable
Q78: What is the earliest stage at which
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents