An Incident Responder has determined that an endpoint is compromised by a malicious threat. What SEDR feature would be utilized first to contain the threat?
When an Incident Responder determines that an endpoint is compromised, the first action to contain the threat is to use the Isolation feature in Symantec Endpoint Detection and Response (SEDR). Isolation effectively disconnects the affected endpoint from the network, thereby preventing the malicious threat from communicating with other systems or spreading within the network environment. This feature enables the responder to contain the threat swiftly, allowing further investigation and remediation steps to be conducted without risk of lateral movement by the attacker.
Jutta
5 months agoFranchesca
6 months agoCaitlin
6 months agoHollis
6 months agoMarcelle
6 months agoKanisha
6 months agoCordelia
7 months agoGilberto
7 months agoLeatha
7 months agoTwana
7 months agoYuonne
8 months agoElza
8 months agoErnest
8 months agoKasandra
11 months agoJohnathon
11 months agoAileen
11 months agoAshleigh
11 months agoReid
11 months agoBonita
11 months agoPamella
12 months agoElli
12 months agoMy
12 months agoPamella
12 months agoAnnita
1 year agoIdella
1 year agoOdelia
11 months agoTesha
11 months agoHana
12 months agoEdna
1 year agoWhitney
1 year agoBobbye
1 year agoMarvel
1 year agoBenton
1 year agoParis
1 year agoBrande
1 year ago