Yeah, I agree. I'm going to go with B) WebFilter log with action=dropped. It just feels more intuitive to me that a 'Contained' event would be associated with a dropped action, rather than a quarantine.
You know, I was thinking the same thing. The WebFilter log with action=dropped could also be a valid answer. This exam is really trying to trip us up with these subtle differences.
I'm not so sure about that. Wouldn't a WebFilter log with action=dropped also generate a 'Contained' event? The question doesn't specify the type of log, just that it should generate a 'Contained' event.
Hmm, this is a tricky one. I think the answer is C) An AV log with action=quarantine. That would generate a 'Contained' event, right? The other options don't seem to fit the description.
Leigha
8 months agoCarmen
8 months agoLucy
8 months agoLeota
8 months agoLina
7 months agoKelvin
7 months agoLonny
8 months agoLuis
8 months agoFlo
8 months agoSheridan
8 months agoCharlie
8 months ago