ATP detects a threat phoning home to a command and control server and creates a new incident. The threat is NOT being detected by SEP, but the Incident Response team conducted an indicators of compromise (IOC) search for the machines that are contacting the malicious sites to gather more information. Which step should the Incident Response team incorporate into their plan of action?
A) Perform a healthcheck of ATP
B) Create firewall rules in the Symantec Endpoint Protection Manager (SEPM) and the perimeter firewall
C) Use ATP to isolate non-SEP protected computers to a remediation VLAN
D) Rejoin the endpoints back to the network after completing a final virus scan
Correct Answer:
Verified
Q102: During a recent virus outbreak, an Incident
Q103: Which two non-Symantec methods for restricting traffic
Q104: In which scenario should an Incident Responder
Q105: An organization is considering an ATP: Endpoint
Q106: An ATP administrator is setting up an
Q108: What is the role of Synapse within
Q109: Which two questions can an Incident Responder
Q110: What is a benefit of using Microsoft
Q111: What are the prerequisite products needed when
Q112: An Incident Responder wants to use a
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents