An Incident Responder documented the scope of a recent outbreak by reviewing the incident in the ATP manager. Which two entity relationship examples should the responder look for and document from the Incident Graph? (Choose two.)
A) An intranet website that is experiencing an increase in traffic from endpoints in a smaller branch office.
B) A server in the DMZ that was repeatedly accessed outside of normal business hours on the weekend.
C) A network share is repeatedly accessed during and after an infection indicating a more targeted attack.
D) A malicious file that was repeatedly downloaded by a Trojan or a downloader that infected multiple endpoints.
E) An external website that was the source of many malicious files.
Correct Answer:
Verified
Q76: Which threat is an example of an
Q77: What does a Quarantine Firewall policy enable
Q78: What is the earliest stage at which
Q79: An Incident Responder runs an endpoint search
Q80: An Incident Responder notices traffic going from
Q82: Which stage of an Advanced Persistent Threat
Q83: Which two user roles allow an Incident
Q84: An Incident Responder is going to run
Q85: Which two steps must an Incident Responder
Q86: Which stage of an Advanced Persistent Threat
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents