ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 196 - SY0-701 discussion

Report
Export

A security analyst is investigating an alert that was produced by endpoint protection software. The analyst determines this event was a false positive triggered by an employee who attempted to download a file. Which of the following is the most likely reason the download was blocked?

A.
A misconfiguration in the endpoint protection software
Answers
A.
A misconfiguration in the endpoint protection software
B.
A zero-day vulnerability in the file
Answers
B.
A zero-day vulnerability in the file
C.
A supply chain attack on the endpoint protection vendor
Answers
C.
A supply chain attack on the endpoint protection vendor
D.
Incorrect file permissions
Answers
D.
Incorrect file permissions
Suggested answer: A

Explanation:

The most likely reason the download was blocked, resulting in a false positive, is a misconfiguration in the endpoint protection software. False positives occur when legitimate actions are incorrectly identified as threats due to incorrect settings or overly aggressive rules in the security software.

Misconfiguration in the endpoint protection software: Common cause of false positives, where legitimate activities are flagged incorrectly due to improper settings.

Zero-day vulnerability: Refers to previously unknown vulnerabilities, which are less likely to be associated with a false positive.

Supply chain attack: Involves compromising the software supply chain, which is a broader and more severe issue than a simple download being blocked.

Incorrect file permissions: Would prevent access to files but not typically cause an alert in endpoint protection software.

asked 02/10/2024
Beena Sagayaraj
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first