Question 56
What is the purpose of a containment policy?
Question 57
Which Real Time Response role will allow you to see all analyst session details?
Question 58
You have an existing workflow that is triggered on a critical detection that sends an email to the escalation team. Your CISO has asked to also be notified via email with a customized message. What is the best way to update the workflow?
Question 59
On a Windows host, what is the best command to determine if the sensor is currently running?
Question 60
Custom IOA rules are defined using which syntax?
