To exclude a specific executable from Application File Access Control monitoring, which action is required?

Prepare for the Symantec Data Loss Prevention (DLP) Exam with targeted quizzes and detailed explanations. Boost your knowledge and confidence with our engaging study tools!

Multiple Choice

To exclude a specific executable from Application File Access Control monitoring, which action is required?

Explanation:
The action relies on configuring how the Data Loss Prevention agent tracks that program, not on moving files or blocking network traffic. In Application File Access Control, you manage a list of applications in the Application Monitoring Configuration, and for each executable you can enable or disable the channels through which its file-access activity is monitored. To exclude a specific executable, add it to the Application Monitoring Configuration and deselect all its channel options so no file-access events from that program are monitored or logged. Other approaches—like moving the executable, removing directories, or using a firewall rule—don’t alter the AFAC monitoring behavior for that app in the policy.

The action relies on configuring how the Data Loss Prevention agent tracks that program, not on moving files or blocking network traffic. In Application File Access Control, you manage a list of applications in the Application Monitoring Configuration, and for each executable you can enable or disable the channels through which its file-access activity is monitored. To exclude a specific executable, add it to the Application Monitoring Configuration and deselect all its channel options so no file-access events from that program are monitored or logged. Other approaches—like moving the executable, removing directories, or using a firewall rule—don’t alter the AFAC monitoring behavior for that app in the policy.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy