Yeah, I agree. I'm going to go with B) WebFilter log with action=dropped. It just feels more intuitive to me that a 'Contained' event would be associated with a dropped action, rather than a quarantine.
You know, I was thinking the same thing. The WebFilter log with action=dropped could also be a valid answer. This exam is really trying to trip us up with these subtle differences.
I'm not so sure about that. Wouldn't a WebFilter log with action=dropped also generate a 'Contained' event? The question doesn't specify the type of log, just that it should generate a 'Contained' event.
Hmm, this is a tricky one. I think the answer is C) An AV log with action=quarantine. That would generate a 'Contained' event, right? The other options don't seem to fit the description.
upvoted 0 times
...
Log in to Pass4Success
Sign in:
Report Comment
Is the comment made by USERNAME spam or abusive?
Commenting
In order to participate in the comments you need to be logged-in.
You can sign-up or
login
Leigha
8 days agoCarmen
9 days agoLucy
10 days agoLeota
11 days ago