A customer has information about a malicious file that has NOT entered the network. The customer wants to know whether ATP is already aware of this threat without having to introduce a copy of the file to the infrastructure.
Which approach allows the customer to meet this need?
Which Advanced Threat Protection (ATP) component best isolates an infected computer from the network?
What does a Quarantine Firewall policy enable an ATP Administrator to do?
Which SEP technologies are used by ATP to enforce the blacklisting of files?
An Incident Responder runs an endpoint search on a client group with 100 endpoints. After one day, the responder sees the results for 90 endpoints.
What is a possible reason for the search only returning results for 90 of 100 endpoints?
An Incident Responder has reviewed a STIX report and now wants to ensure that their systems have NOT been compromised by any of the reported threats.
Which two objects in the STIX report will ATP search against? (Choose two.)
Which stage of an Advanced Persistent Threat (APT) attack do attackers break into an organization's network to deliver targeted malware?
A large company has 150,000 endpoints with 12 SEP sites across the globe. The company now wants to implement ATP: Endpoint to improve their security. However, a consultant recently explained that the company needs to implement more than one ATP manager.
Why does the company need more than one ATP manager?
In which two locations should an Incident Responder gather data for an After Actions Report in ATP? (Choose two.)
Which two widgets can an Incident Responder use to isolate breached endpoints from the Incident details page? (Choose two.)