ENDPOINT-SECURITY5 MIN READ
Decide when to isolate a suspicious endpoint
Choose a containment action for a suspicious endpoint based on evidence, spread risk, and business impact.
A payroll laptop has suspicious outbound traffic, new persistence, and credential-access evidence. The business process is important, but the endpoint may be an active foothold.
Read the full lesson
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in