An Incident Responder has determined that an endpoint is compromised by a malicious threat. What SEDR feature would be utilized first to contain the threat?
When an Incident Responder determines that an endpoint is compromised, the first action to contain the threat is to use the Isolation feature in Symantec Endpoint Detection and Response (SEDR). Isolation effectively disconnects the affected endpoint from the network, thereby preventing the malicious threat from communicating with other systems or spreading within the network environment. This feature enables the responder to contain the threat swiftly, allowing further investigation and remediation steps to be conducted without risk of lateral movement by the attacker.
Kasandra
2 months agoJohnathon
2 months agoAileen
26 days agoAshleigh
27 days agoReid
1 months agoBonita
1 months agoPamella
2 months agoElli
2 months agoMy
2 months agoPamella
2 months agoAnnita
3 months agoIdella
3 months agoOdelia
1 months agoTesha
1 months agoHana
2 months agoEdna
3 months agoWhitney
2 months agoBobbye
2 months agoMarvel
3 months agoBenton
3 months agoParis
3 months agoBrande
3 months ago