Question 21

Why is visibility into AD authentication activity critical?
Response:
  • Question 22

    A trusted application begins performing suspicious actions. Which feature allows fine-grained control over this behavior?
  • Question 23

    Which data sources are typically reviewed during an ICDm investigation?
    (Select all that apply)
  • Question 24

    What is the purpose of Adaptive Protection's Monitor mode?
  • Question 25

    An endpoint exhibits unusual process spawning behavior without a known malware signature. Which EDR capability detects this?