How should a DLP administrator change a policy so that it retains the original file when an endpoint incident has detected a "copy to USB device" operation?
A) Add a "Limit Incident Data Retention" response rule with "Retain Original Message" option selected.
B) Modify the agent config.db to include the file
C) Modify the "Endpoint_Retain_Files.int" setting in the Endpoint server configuration
D) Modify the agent configuration and select the option "Retain Original Files"
Correct Answer:
Verified
Q7: Which action should a DLP administrator take
Q8: When managing an Endpoint Discover scan, a
Q9: A compliance officer needs to understand how
Q10: Which two actions are available for a
Q11: Which option correctly describes the two-tier installation
Q13: What is the correct configuration for "BoxMonitor.Channels"
Q14: Which detection server is available from Symantec
Q15: What detection server type requires a minimum
Q16: What detection server is used for Network
Q17: A DLP administrator has enabled and successfully
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents