Symantec Endpoint Security Complete - R2 Technical Specialist 250-580 Question # 13 Topic 2 Discussion

Symantec Endpoint Security Complete - R2 Technical Specialist 250-580 Question # 13 Topic 2 Discussion

250-580 Exam Topic 2 Question 13 Discussion:
Question #: 13
Topic #: 2

Why is it important for an Incident Responder to copy malicious files to the SEDR file store or create an image of the infected system during the Recovery phase?


A.

To create custom IPS signatures


B.

To test the effectiveness of the current assigned policy settings in the Symantec Endpoint ProtectionManager (SEPM)


C.

To have a copy of the file for policy enforcement


D.

To document and preserve any pieces of evidence associated with the incident


Get Premium 250-580 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.