Which two steps must an Incident Responder take to isolate an infected computer in ATP? (Choose two.)
A) Close any open shares
B) Identify the threat and understand how it spreads
C) Create subnets or VLANs and configure the network devices to restrict traffic
D) Set executables on network drives as read only
E) Identify affected clients
Correct Answer:
Verified
Q80: An Incident Responder notices traffic going from
Q81: An Incident Responder documented the scope of
Q82: Which stage of an Advanced Persistent Threat
Q83: Which two user roles allow an Incident
Q84: An Incident Responder is going to run
Q86: Which stage of an Advanced Persistent Threat
Q87: A large company has 150,000 endpoints with
Q88: What is the minimum amount of RAM
Q89: Which stage of an Advanced Persistent Threat
Q90: An Incident Responder has reviewed a STIX
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents