A user downloads a PDF from the internet that contains a zero-day exploit. The Harmony Endpoint agent is configured with Threat Emulation and Threat Extraction. The policy for both is set to the 'Prevent' action. What is the expected sequence of events when the user attempts to open the file?
sequenceDiagram
participant User
participant Endpoint Agent
participant ThreatCloud
participant Cleaned File
User->>Endpoint Agent: Attempts to open PDF
Endpoint Agent->>ThreatCloud: Sends file for analysis
Note over ThreatCloud: Emulation & Extraction
ThreatCloud-->>Endpoint Agent: ???
Endpoint Agent-->>User: ???
Endpoint Agent-->>Cleaned File: ???
Answer and explanation
Correct answer: B
This describes the behavior of Threat Extraction working in tandem with Threat Emulation. To provide immediate access without risk, Threat Extraction rebuilds the file, removing any potentially malicious active content (like scripts or macros), and delivers this 'clean' version to the user instantly. Simultaneously, the original, unaltered file is sent to the ThreatCloud sandbox for full emulation to detect the zero-day exploit.
Question 2
What communication protocol does Harmony Endpoint management use to communicate with the management server?
Answer and explanation
Correct answer: B
Question 3
What is the time interval of heartbeat messages between Harmony Endpoint Security clients and Harmony Endpoint Security Management?
Answer and explanation
Correct answer: C
Question 4
Which information can we find on the Operational Overview dashboard?