300-745 · Question #17
Refer to the exhibit. A retail company recently deployed a file inspection feature using secure endpoint. The file inspection must detect and prevent the execution of malicious files on machines…
The correct answer is D. Policy rule is in audit mode. The exhibit shows that the malicious file was detected but not quarantined with the note "In audit only mode." This indicates that the secure endpoint policy was set to audit mode, which only logs detections instead of blocking execution. To prevent malicious files from…
Question
Refer to the exhibit. A retail company recently deployed a file inspection feature using secure endpoint. The file inspection must detect and prevent the execution of malicious files on machines. During testing, logs showed that certain malicious files are still being executed despite the presence of the security measure. To understand why the threats are not being blocked, it is essential to investigate the configuration of secure endpoint policies. Which configuration is allowing the files to execute?
Exhibit
Options
- AFiles are not malicious.
- BPolicy must block the network connections.
- CPolicy rule is disabled.
- DPolicy rule is in audit mode.
How the community answered
(34 responses)- A6% (2)
- B3% (1)
- C9% (3)
- D82% (28)
Explanation
The exhibit shows that the malicious file was detected but not quarantined with the note "In audit only mode." This indicates that the secure endpoint policy was set to audit mode, which only logs detections instead of blocking execution. To prevent malicious files from running, the policy must be switched from audit mode to enforcement (block) mode.
Topics
Community Discussion
No community discussion yet for this question.
