ExamGecko
Question list
Search
Search

Question 48 - 156-315.81 discussion

Report
Export

During inspection of your Threat Prevention logs you find four different computers having one event each with a Critical Severity. Which of those hosts should you try to remediate first?

A.
Host having a Critical event found by Threat Emulation
Answers
A.
Host having a Critical event found by Threat Emulation
B.
Host having a Critical event found by IPS
Answers
B.
Host having a Critical event found by IPS
C.
Host having a Critical event found by Antivirus
Answers
C.
Host having a Critical event found by Antivirus
D.
Host having a Critical event found by Anti-Bot
Answers
D.
Host having a Critical event found by Anti-Bot
Suggested answer: D

Explanation:

The host having a Critical event found by Anti-Bot should be remediated first, as it indicates that the host is infected by a botnet malware that is communicating with a Command and Control server. This poses a serious threat to the network security and data integrity. The other events may indicate potential malware infection or attack attempts, but not necessarily successful ones.Reference:Threat Prevention Administration Guide

asked 16/09/2024
Luis Elola
28 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first