Solved

An Incident Responder Launches a Search from ATP for a File

Question 93

Multiple Choice

An Incident Responder launches a search from ATP for a file hash. The search returns the results immediately. The responder reviews the Symantec Endpoint Protection Manager (SEPM) command status and does NOT see an indicators of compromise (IOC) search command. How is it possible that the search returned results?


A) The search runs and returns results in ATP and then displays them in SEPM.
B) This is only an endpoint search.
C) This is a database search; a command is NOT sent to SEPM for this type of search.
D) The browser cached result from a previous search with the same criteria.

Correct Answer:

verifed

Verified

Unlock this answer now
Get Access to more Verified Answers free of charge

Related Questions

Unlock this Answer For Free Now!

View this answer and more for free by performing one of the following actions

qr-code

Scan the QR code to install the App and get 2 free unlocks

upload documents

Unlock quizzes for free by uploading documents