Organizational security policy requires a host-based firewall on endpoints. Some endpoints have applications where documentation depicting network traffic flows is not readily available. Which of the following ENS
10.5 firewall features should be used to develop rules for their firewall policy?
A. Location-aware Groups
B. Trusted Executables
C. Adaptive Mode
D. Trusted Networks
正解:D
質問 2:
The ePO administrators have already tuned and configured dynamic application containment rules within the policy. In which of the following ways will dynamic application containment protect against malware once enforcement is enabled?
A. The ENS client will receive the reputation as "highly suspicious" from either the McAfee GTI or TIE server, and then immediately uninstall the application on the system.
B. The scan engine will learn the behavior of the application and send up to GT1 for analysis, and then receive an action to block all actions from the application's process.
C. The adaptive threat protection scanner will send the file automatically to a preconfigured "Sandbox" folder and analyze the application for malicious features before use.
D. If an application's reputation is below the threshold while triggering a block rule and is not an excluded application, malicious behavior of the application will be contained.
正解:D
質問 3:
An ENS administrator wants the end user to be able to view the web safety information. In addition to enabling Web Control, which of the following describes the requirements for this?
A. The Web Control Plug-in site report must be enabled on the browser toolbar.
B. The Web Control Plug-in must be enabled in the browser, and "Warn" must be selected in Action Enforcement.
C. The Web Control Plug-in must be enabled in the browser, and the client browser toolbar must be enabled.
D. Content Action settings must be configured to specify the action to apply according to the site rating.
正解:A
質問 4:
On Windows 8 and 10 machines, Windows places a flag in the tile of an app, causing Windows to notify the user of a problem and directing the user to the Windows Store to reinstall. This flag is placed on the tile when the Threat Prevention scanner detects a threat in the path of an installed Windows Store app, and marks the application as:
A. suspicious.
B. malicious.
C. tampered.
D. questionable.
正解:B
質問 5:
A company's security posture requires the ENS firewall to be enabled; however, the team is unsure of communication flows in the environment. In which of the following modes should the ePO administrator deploy the firewall policy to achieve flow awareness?
A. Observe Mode
B. Adaptive Mode
C. Interface Mode
D. Enforce Mode
正解:C
質問 6:
An ePO administrator wants to configure system utilization for on-demand scanning to conform to best-practice recommendations based on the ENS Product Guide. To do this, the administrator should:
A. set system utilization to "Low" for systems with end-user activity and "Low" for systems with large volumes/little end-user activity.
B. set system utilization to "Below Normal" for systems with end-user activity and "Normal" for systems with large volumes/little end-user activity.
C. set system utilization to "Normal" for systems with end-user activity and "Low" for systems with large volumes/little end-user activity.
D. set system utilization to "Low" for systems with end-user activity and "Normal" for systems with large volumes/little end-user activity.
正解:C
質問 7:
An ENS administrator wants to dynamically create firewall rules required for the environment. In Enable Firewall Policies/Options, which of the following should be utilized?
A. Log all blocked traffic
B. Log all allowed traffic
C. Adaptive mode
D. Retain existing user added rules
正解:A
1642 お客様のコメント





Motonaga -
55歳の私が簡単MA0-107合格出来ました。
一度落ちて、再チャレンジでしたが、この本はわかりやすかったです。