Browse all practice questions for the WatchGuard Endpoint Security Essentials Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Ace the WatchGuard Endpoint Security 2026 Test – Defend and Dominate Your Future! course image
All questions

These questions are part of the practice quiz. Start practicing

  • Which action starts a local, immediate scan of the host?
  • Which term refers to home or office networks with trusted users?
  • Which term describes the mechanism regulating user access to web resources?
  • To perform an in-depth scan of all connected storage devices, you would choose which scan type?
  • Which term is described by 'files matching known viruses for detection'?
  • Which alert would be raised when a brand-new unmanaged computer appears?
  • Which protection stops exploit attacks and notifies the user?
  • Which item is used to delete duplicate Endpoint Security IDs?
  • What technique does EPP use to identify malware?
  • Which term describes limited access in public places like cafes?
  • Which alert notifies when attack indicators are detected?
  • Which term identifies applications needing patches or updates?
  • Which configurations pertain to endpoint workstations?
  • Which task is not yet active or scheduled?
  • Programs scanning for and removing malware.
  • Which feature detects threats from HTTP and encrypted web traffic?
  • Which setting controls network connectivity and security?
  • Which term refers to attacks that exploit legitimate software tools?
  • Insights derived from network data for security.
  • Which tab lists inbound connection attempts from remote computers?
  • Which element shows the overall risk level for a given computer?
  • Which alert notifies when a new unmanaged computer is found?
  • Which vulnerability exploitation targets CVE-2019-0708 in Windows?
  • Which term can have multiple endpoint security licenses?
  • Which term describes a group replicating the Active Directory structure?
  • Which term refers to deploying fake files to catch ransomware?
  • Which term describes the automatic exchange of data between directory services and endpoint protection?
  • Which term describes protection that prevents attackers from injecting and executing code within software?
  • Which term matches the description: Defines subnet for scanning unmanaged computers?
  • Which protection blocks unauthorized access to network resources?
  • Which term represents the overall landscape of cybersecurity threats and defenses?
  • Software applications designed to enhance work efficiency.
  • Critical Risk status is described as:
  • Which outcome is a direct result of blocking known ransomware URLs?
  • Which term defines groups that support all operations, including predefined ones?
  • Which term defines the mode that prevents exploitation of vulnerabilities in applications?
  • Which setting provides the ability to temporarily enable or disable protection?
  • Which term describes a tool for detailed analysis of security events?
  • Which term corresponds to the definition: Subset of EDR with XDR capabilities via ThreatSync?
  • Which term is described as observing for malware patterns using heuristics?
  • Which term is the process of examining past security incidents to determine root causes?
  • Which setting group applies to the computer or device level for software installation and updates?
  • What is the term for keys that enable data recovery and are managed centrally?
  • What is the process of updating software to fix vulnerabilities called?
  • Which capability activates a pre-configured task to run on a schedule?
  • Which term refers to a proxy within the corporate network?
  • Which term matches the description: Specifies private IPs for targeted searches?
  • Which option means the user is prompted to restart until action is taken?
  • Which term describes the different durations and formats of licenses available for MSSP subscriptions?
  • Which setting governs temporary enable/disable of protection?
  • Which term matches the description: Specifies private IPs for targeted searches?
  • Real-time monitoring to block advanced security threats.
  • Which dashboard displays security risk levels assigned to computers?
  • Which approach continuously monitors executables with no scheduled scans needed?
  • Which term refers to a defined window during which protections may be temporarily relaxed or delayed before a license expires?
  • Which category provides notifications for security events and issues?
  • Which statement best describes the role of Phishing Detection in endpoint security?
  • Which component displays the history of risk counts and types?
  • What is the multi-layered defense model for endpoint security?
  • Which icon opens the WatchGuard EPDR agent from the system tray?
  • Which term refers to the agent software designed to prevent malware and detect activity on endpoints?
  • Which interface is used to oversee endpoint security settings?
  • Which status represents suspicious patterns awaiting administrator analysis?
  • Which WatchGuard solution is used for security analytics and reporting?
  • Which feature restricts and controls access to devices?
  • Which term refers to registers rogue domain controllers to push changes into Active Directory?
  • Which term is bait used to detect ransomware attacks?
  • Which policy overwrites manual settings with new inherited settings?
  • Which protection defends against malware and virus threats?
  • Which condition resolves autonomously after retries, with no alert generated?
  • Which term is software protecting individual devices from threats?
  • Which technology detects malware by analyzing behavior patterns rather than signatures?
  • Which tab lists detected malware and vulnerabilities?
  • Which term describes the standard image prepared for deployment across machines?
  • Which term corresponds to the definition: Configurations that enhance device protection?
  • Which term is used for third-party software that can be removed to prevent installation conflicts?
  • Which term defines configurations applied to all computers in a group?
  • What is the profile called that configures settings on individual computers?
  • Which term matches the description: Requires VPN connections to meet security standards?
  • Prevents exploitation of vulnerabilities in applications.
  • Which term best encapsulates the set of options for detecting various cybersecurity threats?
  • Which item defines the criteria used to determine endpoints for deletion?
  • Which component summarizes events and indicators for network security?
  • Which configurations are tailored for server environments?
  • Generates extended telemetry in Audit mode.
  • Which term stands for extended detection and response across multiple environments?
  • Which of the following describes how the EICAR test file is used?
  • Which feature sends an audible alarm to the device?
  • Which description corresponds to disabling blocking of external RDP connections?
  • Which term describes home or office networks with trusted users?
  • Which term matches the description: Domains where the discovery computer searches?
  • Which term identifies malware through generic and heuristic methods?
  • Security process requiring multiple verification methods.
  • Which option ensures manual overrides remain intact even when new inherited settings are introduced?
  • Which term is associated with signs indicating potential security breaches?
  • Defines the system's response to unknown files.
  • Which tab logs actions performed by users, such as edits and deletions?
  • Which indicator signals that an attack is likely occurring?
  • What prevents unauthorized code execution in applications?
  • Which feature blocks all communications for an at-risk computer?
  • Which option stores updates for deployment to multiple machines on the network?
  • Which action initiates an immediate scan of the computer?
  • Displays list of patches for installation.
  • Which capability activates a configured task in the scheduler?
  • Which function exports logs to CSV for external use?
  • Which term is best described as ongoing, real-time observation of system changes for security analysis?
  • Which protection blocks attacks exploiting vulnerabilities in services?
  • Which setting specifies files and paths not to scan?
  • Which option does IOA stand for?
  • Scan Tasks are best described as:
  • Which component monitors and responds to endpoint threats?
  • Security flaws not yet addressed by updates.
  • Which action remotely deletes all content on the device?
  • What is the recommended method to distribute the WatchGuard EPDR agent installer?
  • What term describes settings passed down from higher-level groups?
  • Which dashboard would you use to identify and track vulnerabilities across network devices?
  • Which concept refers to the automated labeling of processes as malware or benign?
  • Which statement describes the agent's daily data usage?
  • Which scan type is used to scan selected storage devices and paths?
  • Which term describes the process of activating an endpoint security license?
  • Which term corresponds to the definition: Actions taken to neutralize security threats?
  • Which setting requires a password to disable anti-tamper settings?
  • Which data element contains suspicious patterns detected in event data flow?
  • Which term best matches the internal network used for data exchange?
  • Which setting restarts both servers and workstations automatically after updates?
  • Which technique simulates domain controller behavior to retrieve passwords?
  • Which term corresponds to the definition: Basic configurations for managing endpoint security?
  • No Risk is shown by which color?
  • Which term corresponds to 'Options for detecting various cybersecurity threats'?
  • Which status indicates analyzed patterns marked as resolved by administrator?
  • Which term refers to the list that contains devices not currently managed by endpoint security?
  • Which term refers to the ongoing process of applying fixes to software to close security gaps?
  • Which dashboard evaluates security vulnerabilities in network devices?
  • Which term describes the top-level grouping structure?
  • Which category governs behaviors for server and its configuration options?
  • Patching vulnerabilities to avert future security breaches.
  • Which UI tab organizes devices using filters and custom groups?
  • Which setting would you adjust to control whether the system restarts automatically after updates?
  • Which term refers to malware that operates in memory and evades detection?
  • What concept describes a cap on the number of endpoint devices that can be managed or trialed?
  • Which term represents an integrated security approach spanning endpoints, networks, and cloud environments?
  • Blocking known ransomware URLs primarily prevents endpoints from connecting to which type of resource?
  • Which tile shows the highest risk level detected on a computer?
  • Which alert notifies when previously allowed files are classified?
  • Which feature deletes endpoints automatically based on predefined rules?
  • Which concept describes the root group containing all other groups?
  • Which term matches the description: Used for remote installation of WatchGuard Agent?
  • Which visual element in the system tray gives quick access to the EPDR agent?
  • What service manages computers within a domain?
  • What term means configurations applied to all computers in a group?
  • Which term corresponds to the definition: Endpoint Detection and Response for threat management?
  • Which term refers to rules created to identify potential security threats?
  • Which detects hacking tools and potentially unwanted programs?
  • Which UI control filters data for the last 7 days, month, or year?
  • Which term refers to computers that have been deleted and are unprotected?
  • What is the deletion timeframe for endpoints?
  • Which setting requires a password to uninstall security software?
  • Which term refers to simulating domain controller behavior to retrieve passwords?
  • Enables pop-up alerts for blocked files.
  • Which technique is used to block vulnerability exploit attacks?
  • Blocks unknown programs from untrusted sources.
  • Which term designates the component used to manage proxies defined by WatchGuard?
  • Which term matches the description: Cache computer serves approximately 1,000 connections?
  • Which feature requires additional verification for access?
  • Medium Risk status is represented by:
  • Which feature monitors connections to reduce infection risks?
  • Which term best describes the protection of devices connected to a network?
  • Which term describes continuous observation of potential security risks?
  • Options to reinstall protection immediately or later.
  • Which design influences the deployment strategy for agents?
  • Which term matches the definition: Basic configurations for managing endpoint security?
  • Which component is used to manage and organize specific computers into custom groups?
  • Which feature decompresses and scans the contents of compressed files?
  • Which protection guards against malware when the system is started in Safe Mode?
  • Which feature creates snapshots of computer files?
  • Which term matches the definition: Integrated approach for security management and response?
  • Which option allows or denies program communication on devices?
  • Which feature is designed to provide protection before third-party drivers initialize?
  • Which term identifies devices that require endpoint security installation?
  • Which term denotes in-depth analysis of attempted attacks using forensics?
  • Which area describes weaknesses in software used to access the internet that attackers may exploit?
  • Which term describes features that enhance EPDR with advanced detection capabilities?
  • Which page is used to manage and organize devices in WatchGuard?
  • Which outcome best describes blocking known ransomware URLs?
  • Which technique registers rogue domain controllers to push changes into AD?
  • Which feature displays risks associated with a specific computer?
  • Which tab shows telemetry data collected for the computer?
  • Which protection is designed to defend against malware and viruses?
  • Which alert is raised for installation errors affecting protection?
  • What happens to a deleted computer's protection status?
  • Which term describes techniques that use legitimate tools to carry out wrongdoing on endpoints?
  • Which term is used for accounts that manage multiple endpoint licenses for customers?
  • What is the organizational method using folders and subfolders?
  • What term represents fixed groups of computers created for management purposes?
  • Which term identifies unprotected computers on the network?
  • What is the purpose of Scheduled Reports?
  • Which detects malware behavior through pattern recognition?
  • Phishing detection at the endpoint primarily helps identify which of the following?
  • Which term represents suspicious patterns that indicate an attack?
  • Which option indicates workstations restart automatically while servers do not?
  • Which term corresponds to the definition: Analyzing behavior patterns to detect anomalies?
  • Which term denotes a grouping that remains fixed and does not update with filters?
  • Which scan type corresponds to a quick scan of memory and system directories?
  • Which condition requires user intervention due to insufficient disk space?
  • Which component provides a guided install experience for the WatchGuard Agent?
  • Which term describes the criteria used to group computers based on conditions?
  • Which term describes common filters included with Endpoint Security products?
  • Which dashboard gives a summarized view of security status over time?
  • Which term matches the description: Cached for 30 days for management?
  • Which term corresponds to the definition: Integrated approach for security management and response?
  • Which option enables detection of malicious programs?
  • Which term refers to centrally managed keys used to recover encrypted data?
  • Which condition occurs when no licenses are available after registration?
  • What term describes controlling which software can run on endpoints, blocking others?
  • Which term is used to describe restrictions on the number of endpoints that can be enrolled for protection?
  • What is the primary purpose of configuring regular antivirus scans?
  • Duration malware remains undetected in a system.
  • What credential is required to access the Administrator panel?
  • Which classifies processes to minimize endpoint risk?
  • What is the purpose of the EICAR test file in endpoint security testing?
  • In addition to real-time protection, scheduled antivirus scans help ensure:
  • Which app is designed for Android and iOS devices for endpoint security?
  • Which alert notifies for each malware detected in real-time?
  • Which term is used for networks in private spaces with trusted users?
  • Which option schedules patch installation?
  • Which capability allows you to determine the device's location using its server coordinates?
  • Which protects processes from fileless malware attacks?
  • Which alert notifies when blocked devices are accessed?
  • Which term describes attacks that execute malicious scripts to compromise systems?
  • Which term corresponds to branches representing domains in Active Directory?
  • Which setting stores updates for other computers on the network?
  • Which dashboard monitors access policies for endpoint devices?
  • Which deployment method is described as a Windows-based approach to install software across several machines?
  • Creates a task for future patch installation.
  • Which option is used to filter TCP/IP traffic based on predefined criteria?
  • Which term is associated with signs indicating potential security breaches?
  • Which generates security intelligence and IT insights?
  • Which component summarizes events and indicators for network security?
  • What tool is used for troubleshooting with WatchGuard Support?
  • What deployment approach installs software on devices over the network?
  • Which dashboard provides an overview of network security status over time?
  • Which term describes attacks that use legitimate software for malicious purposes?
  • Which feature manages and restricts device access?
  • Which term refers to a default behavior where child groups inherit settings from their parent unless overridden?
  • Dynamic environment of evolving security threats.
  • Which term matches the definition: Endpoint Detection and Response for threat management?
  • Which term refers to malware that encrypts files, demanding ransom for access?
  • Which term matches the definition: Any device connected to a network?
  • What is the Windows-specific method for deploying software across machines in a Windows environment?
  • Internal network of an organization for data exchange.
  • Which protection blocks uninstallation without authorization?
  • Which term describes alerts triggered by changes in computer protection status?
  • Which term enables use of endpoint security modules?
  • Which term matches the description: Limits search areas for unmanaged computers?
  • Which term matches the description: Defines subnet for scanning unmanaged computers?
  • Which scans compressed files for malware upon extraction?
  • Tracks program activity and detects malicious programs.
  • Shared data to enhance malware detection capabilities.
  • Can be removed to prevent conflicts during installation.
  • Which term describes protection measures for mobile endpoints in networks?
  • Which term is cached until they are outdated?
  • Which category uses heuristics for improved detection rates?
  • Which term describes the maximum depth for subgroups within the structure?
  • Which term describes analysis based on user behavior patterns?
  • What is the guided process for installing the WatchGuard Agent?
  • Which term best matches a software tool used to generate in-depth security event reports?
  • Which term describes data that must be protected from unauthorized access?
  • What is the installation method that involves deploying directly on individual devices?
  • Which section provides quick links to filtered detailed lists?
  • Which term configures communication with networked computers?
  • To export security event logs for external analysis, which feature should you use?
  • Which term describes groups that automatically update membership based on conditions?
  • Which component is designed as an optional module for data control in Europe?
  • Which policies enforce rules based on device group membership?
  • Which action deletes all content from the device?
  • Which alert would indicate an intrusion attempt has been blocked?
  • Options include Audit, Block, and Do Not Detect.
  • Reports threats without blocking or disinfecting files.
  • Which term describes a vulnerability that enables impersonation of domain controllers by exploiting Netlogon weakness?
  • In-depth scan of all connected storage devices. Which scan type is used?
  • Which alert signals when unknown programs are blocked?
  • Which setting restarts servers automatically after updates, while workstations do not?
  • Which term describes a grouping that can perform all operations including predefined tasks?
  • Anti-Theft Dashboard provides remote actions for mobile devices.
  • Which alert indicates detected malware URLs on a 15-minute interval?
  • Which interface displays agent status and blocked actions?
  • Which platform is NOT listed as a supported client platform for the agent?
  • Which outcome is expected when a system detects the EICAR test file?
  • Which setting is designed to protect against threats when starting the system in Safe Mode?
  • Which term describes scanning email for threats via the POP3 protocol?
  • Which term defines the maximum number of endpoint devices allowed under a trial or service?
  • Which element shows actions taken by monitored programs on computers?
  • Which setting governs restarting after updates?
  • Which tab lists detected malware and vulnerabilities?
  • What provides direct Internet access without using a proxy?
  • Which tab lists inbound connection attempts from remote computers?
  • Which term refers to reporting to users when files are blocked?
  • Which term corresponds to the definition: Individuals exploiting vulnerabilities for harmful purposes?
  • Which alert is generated when malware URLs are detected in traffic?
  • What term describes the automated installation method that uses a disk image?
  • What defines which endpoints to delete automatically?
  • Which term matches the description: Used for remote installation of WatchGuard Agent?
  • What is the central console used to configure endpoint security settings and monitor status?
  • Which updates are essential for threat identification?
  • What feature prevents unauthorized software execution?
  • Which alert reports each exploit attempt detected?
  • Which term describes exploiting vulnerabilities before patches are available?
  • Which option automatically identifies network type based on rules?
  • Which term lists proxies within the network?
  • Uses signature files to identify known malware.
  • Displays detailed information about selected computers.
  • Which term describes attacks that use legitimate tools and techniques in an authorized operating environment to perform malicious actions?
  • Which term corresponds to 30-day trials for various WatchGuard products?
  • Which tool is used to delete duplicate Endpoint Security IDs?
  • Which option displays detailed information about the selected computers?
  • Which is a long-term targeted cyberattack on specific entities?
  • Which is an optional module for data management in Europe?
  • Displays number and types of risks over time.
  • Which term refers to threats that exploit vulnerabilities not yet known to vendors?
  • Which feature is used to locate the device using server coordinates?
  • What are the specifications needed for a successful agent installation?
  • Which term finds proxies using WPAD protocol?
  • Prevents execution of malware and unknown programs.
  • What element shows the overall security posture over time?
  • Which tool tests client communication with cloud resources?
  • High Risk status is communicated as:
  • Which term matches the description: Limits search areas for unmanaged computers?
  • Which term best describes identified browser-related weaknesses that attackers commonly exploit?
  • Which product combines EPP and EDR capabilities for endpoint security?
  • Which tab details installed hardware and resource usage?
  • Which term identifies applications needing patches or updates?
  • Which term matches the description: Cache computer serves approximately 1,000 connections?
  • Which feature updates groups based on defined filters?
  • Which concept describes subgroups inheriting settings from their parent groups?
  • Which exploit CVE-2020-1472 allows impersonation of domain controllers?
  • Which is a managed service for protecting IT assets?
  • Which element would you use to view ongoing protection activities and exceptions?
  • Which term describes automatically identifying network type based on rules?
  • Tracking actions of running applications for security.
  • Which dashboard provides information on blocked Internet content and emails?
  • Which product protects endpoints from known and unknown threats?
  • Which tab shows telemetry collected for the computer?
  • What is the identifier for each computer in the management UI?
  • Which alert would you consult if attack indicators have been detected on the system?
  • Which tool checks client connectivity to cloud resources?
  • Which term is the investigation of security incidents to understand breaches?
  • Which exploit name corresponds to a Windows SMB remote code execution vulnerability disclosed in 2017?
  • Which term designates the tab that defines cache computers for updates and patches?
  • Which feature provides a centralized view for managing endpoints?
  • Which term can have only one endpoint security license?
  • Which term describes tools that leverage software vulnerabilities for attacks?
  • Combines traditional methods with cloud-based analysis.
  • Which setting allows customization of email alerts for network administrators?
  • Which term denotes the overall root container that contains all groups?
  • Remote actions for Android and iOS devices.
  • Which statement best describes Scheduled Antivirus Scans?
  • Which element shows actions taken by monitored programs on computers?
  • Which term identifies the first computer added for discovering others?
  • Software protecting individual devices from threats.
  • Which term is the first computer added for discovering others?
  • Which term best describes a defense strategy that stacks multiple protective layers on endpoints?
  • Which term describes the encryption module for securing sensitive data?
  • Which ports are required for remote installation?
  • If you want a single computer to use a configuration that differs from its parent group, which mechanism is used?
  • Which term refers to the agent software that prevents malware and detects activity on endpoints?
  • Which set of platforms are supported by the WatchGuard Agent?
  • Which alert would you configure to be notified when a malware is detected in real-time?
  • Which term matches the description: Windows 8.1+, macOS 10.13+, Android 6+ required?
  • Which term identifies encryption capability offered by WatchGuard?
  • What term refers to automatic updates between Active Directory and Endpoint Security?
  • Which operation locks the device requiring a code to access?
  • Which concept specifies a cap on the number of endpoint devices in a given plan?
  • Which feature provides an extra verification step for access?
  • Which term corresponds to the definition: Feature enabling extended detection and response capabilities?
  • Which feature is responsible for monitoring and responding to endpoint threats?
  • Which option specifies that workstations restart automatically, while servers require manual restart?
  • Which term describes the setting that excludes files or paths from scans?
  • Which action is a benefit of running regular antivirus scans?
  • Which uses behavioral analysis to detect and block threats?
  • Which term defines computers acting as WatchGuard proxies?
  • Which threat category involves executing code scripts to compromise systems?
  • Which alert notifies for potentially unwanted programs detected?
  • Securing data by converting it into an unreadable format is called what?
  • Which term pertains to filtering TCP/IP traffic based on defined criteria?
  • Which term denotes evidence suggesting a security breach has occurred?
  • Which term describes the structure of groups and subgroups up to ten levels?
  • If a computer is missing a license, which alert is raised?
  • Which term matches the description: Unique identifier for endpoint enforcement?
  • Which alert category indicates when a program is blocked because it is unknown?
  • Which term detects anomalous application use on endpoints?
  • What term refers to a proxy within the company network for Internet access?
  • Files matching known viruses for detection.
  • Files/paths excluded from scans, no protection applied.
  • What describes automatic updates of detection rules used to identify malware?
  • Which alert covers detected network attacks?
  • Which term matches the definition: Subset of EDR with XDR capabilities via ThreatSync?
  • What is the name of the client software used for endpoint device communication with WatchGuard?
  • Which item is used to customize email alerts for network administrators?
  • Which term describes a security capability that provides detection and response across multiple environments?
  • Which setting specifies how often client software updates?
  • Which concept analyzes behavior to identify suspicious activities?
  • Which tab logs system events not initiated by users?
  • What is the primary purpose of blocking known ransomware URLs?
  • Which exploit targets CVE-2017-0144 in the SMB protocol?
  • Which option allows viewing report contents before scheduling or printing?
  • Which WatchGuard term refers to a service that classifies processes to minimize endpoint risk?
  • Which term indicates no security threats?
  • Which setting would you configure to exclude specific files or paths from scanning?
  • Which feature monitors connections to reduce infection risks?
  • Which manages patches for OS and application vulnerabilities?
  • Which vulnerability category focuses on flaws in browser software that attackers exploit?
  • Which option schedules a future scan for a computer?
  • Which term corresponds to the definition: Any device connected to a network?
  • Which term is defined as Shared data to enhance malware detection capabilities?
  • Which term is used for settings inherited from higher-level groups?
  • Which security solution combines prevention, detection, and response to threats?
  • Which term describes alerts triggered by changes in computer protection status?
  • What term describes the range of operating systems supported by the endpoint agent?
  • Which company provides cybersecurity solutions for enterprises?
  • What is the purpose of My Lists?
  • Which section provides quick links to filtered detailed lists?
  • Which setting allows directly assigning values that override inherited ones?
  • Reinstalls client software from a discovery computer.
  • Which is the list of approved applications for use?
  • Which term describes attackers who use legitimate tools for malicious purposes?
  • Which term defines cache computers for updates and patches?
  • Information requiring protection from unauthorized access.
  • Which term describes security that uses signature files to identify malware?
  • Which app is installed on Android and iOS devices?
  • What term describes registry edits and file modifications sent to security analysis?
  • Reinstalls client software from a discovery computer.
  • Which feature prevents unauthorized uninstallation of security software?
  • Which ports must be accessible by the agent for operation?
  • Which dashboard focuses on potential signs of network attacks?
  • Which alert signals unprotected computers or errors?
  • Which item executes a process to verify advanced protection?
  • Which feature allows restoring previous versions of files by taking snapshots?
  • What term refers to weaknesses in browsers that attackers exploit?
  • Which tile presents the top risks found on computers in descending order?
  • Which alert fires when a computer lacks a license?
  • Which term describes malware that operates in memory and avoids traditional detection techniques?
  • Which term describes a platform that integrates prevention, detection, and response for endpoints?
  • Which term describes exploits targeting vulnerabilities not yet known?
  • Which option lets you view report contents before scheduling or printing?
  • What term defines intermediary computers for network communication?
  • What is the term for devices that have not yet been onboarded into endpoint security?
  • Which alert is triggered when an intrusion attempt is blocked?
  • Which feature logs user sessions and actions in the management UI?
  • Verbose Mode generates extended telemetry in Audit mode.
  • Which configuration setting involves listing multiple file types separated by commas?
  • Which term refers to verifying identity using multiple methods?
  • Which term identifies signals that an attack is likely occurring?
  • Which term refers to the practice of combining traditional methods with cloud-based analysis to enhance protection?
  • Which capability captures a photo of the device user (Android only)?
  • Which term defines the category of responses to unknown files including Audit, Hardening, and Lock?
  • Which alert notifies of detected phishing attacks every 15 minutes?
  • Which tab lists installed software and version changes?
  • What is the process of removing software from devices remotely, Windows only?
  • Which set defines rules for devices based on their group membership?
  • Which statement accurately describes the EICAR test file?
  • What option retains manual settings while applying new inherited ones?
  • Which dashboard shows potential signs of network attacks?
  • Which setting contains profiles for software installation and updates?
  • Which term is described as a group containing all Active Directory domains?
  • Which of the following would indicate a phishing email?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy