An Incident Responder documented the scope of a recent outbreak by reviewing the incident in the ATP manager. Which two entity relationship examples should the responder look for and document from the Incident Graph? (Choose two.)
A) An intranet website that is experiencing an increase in traffic from endpoints in a smaller branch office.
B) A server in the DMZ that was repeatedly accessed outside of normal business hours on the weekend.
C) A network share is repeatedly accessed during and after an infection indicating a more targeted attack.
D) A malicious file that was repeatedly downloaded by a Trojan or downloader that infected multiple endpoints.
E) An external website that was the source of many malicious files.
Correct Answer:
Verified
Q130: What is the purpose of Email Impersonation
Q131: An ATP Administrator set up ATP: Network
Q132: Which type of assessment is unavailable within
Q133: Which threat is an example of an
Q134: What is the standard Time to Live
Q136: A customer has information about a malicious
Q137: Why should an administrator configure Symantec Validation
Q138: An ATP administrator is setting up correlation
Q139: A network control point discovered a botnet
Q140: Which best practice does Symantec recommend with
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents