A network control point discovered a botnet phone-home attempt in the network stream.
Which detection method identified the event?
A. Vantage
B. Antivirus
C. Cynic
D. Insight
正解:B
質問 2:
Why is it important for an Incident Responder to review Related Incidents and Events when analyzing an incident for an After Actions Report?
A. It ensures that the Incident is resolved, and the responder can close out the incident in the ATP manager.
B. It ensures that the Incident is resolved, and the threat is NOT continuing to spread to other parts of the environment.
C. It ensures that the Incident is resolved, and the responder can determine the best remediation method.
D. It ensures that the Incident is resolved, and the responder can clean up the infection.
正解:B
質問 3:
What is the second stage of an Advanced Persistent Threat (APT) attack?
A. Capture
B. Incursion
C. Discovery
D. Exfiltration
正解:B
質問 4:
In which scenario would it be beneficial for an organization to eradicate a threat from the environment by deleting it?
A. The Incident Response team is identifying the scope of the infection and is gathering a list of infected systems.
B. The Incident Response team is reviewing detections in the risk logs and assigning a High-Security Antivirus and Antispyware policy in the Symantec Endpoint Protection Manager (SEPM).
C. The Incident Response team is analyzing the file to determine if it is a threat or a false positive.
D. The Incident Response team completed their analysis of the threat and added it to a blacklist.
正解:D
質問 5:
An Incident Responder has reviewed a STIX report and now wants to ensure that their systems have NOT been compromised by any of the reported threats.
Which two objects in the STIX report will ATP search against? (Choose two.)
A. Registry entry
B. SHA-1 hash
C. MD5 hash
D. SHA-256 hash
E. MAC address
正解:C,D
質問 6:
What is the minimum amount of RAM required for a virtual deployment of the ATP Manager in a production environment?
A. 48 GB
B. 16 GB
C. 64 GB
D. 32GB
正解:A
質問 7:
Which best practice does Symantec recommend with the Endpoint Detection and Response feature?
A. Create a unique Cynic account to provide to ATP
B. Create a unique Symantec Protection Manager (SEPM) administrator account to provide to ATP
C. Create a unique Symantec Messaging Gateway account to provide to ATP
D. Create a unique Email Security.cloud portal account to provide to ATP
正解:B
Tamura -
実際に250-441試験は、どの本でもあてはまることかと思いますが、載っている内容の半分くらいが出る印象でした。