SECURITY EXAM
Contextual Detections for Fileless Attacks Layer - ANSWERS-
(Layered Protection) Refers to the many components that run in the
background and perform behavioral analysis to automatically detect
threats, trigger alerts, and block malicious content
Fileless Attacks - ANSWERS-(Layered Protection)
-Script-based attacks
-Web Browser vulnerabilities
-Attacks that use existing legitimate software tools
Anti-Exploit Technology Layer - ANSWERS-(Layered Protection)
Protects running process on endpoints from compromise. This helps
to prevent fileless malware from gaining a foothold on the system
Zero-Trust Application Service Layer - ANSWERS-(Layered
Protection) combination of security solutions and technologies that
operate across the network to analyze endpoints, users, data,
applications, and cloud communications
Threat Hunting Service Layer - ANSWERS-(Layered Protection)
Detects anomalous use of trusted applications on endpoints. It uses
hacker detection to find attackers who use LOTL techniques as well
as behavior modeling to identify malicious use by employees
, Computers Page - ANSWERS-(Computer management) add, group,
and manage all the devices managed by watchguard endpoint security
General Settings - ANSWERS-(Computer management) -User Audit
Logs
-Per-Computer Settings
-Network Settings
-Network Services
-Computer Maintenance
-Alerts
Status Page - ANSWERS-(Computer management) Use dashboards,
lists and tasks to monitor threats to the computers and devices on your
network
Security Settings - ANSWERS-(Computer management) -Workstation
and server settings
- Indicators of Attack
- Risks
- Program Blocking
- Authorized Software
- Mobile Devices
- Patch Managment