Library helpdesk analysts can see Carbon Black Cloud alerts but cannot isolate a compromised kiosk. NSX-T is not in the kiosk path. What should the security administrator fix?
Select an answer to reveal the explanation.
Short Explanation
Seeing the alarm is not the same as holding the keys to lock the kiosk. Isolation and Live Response live in the Carbon Black Cloud role, not in NSX or a public RDP hole.
Full Explanation
Carbon Black Cloud console actions such as device isolate and Live Response are granted through RBAC roles. Missing those permissions explains an analyst who can view alerts but cannot contain the endpoint. NSX-T Identity Firewall is not in the kiosk path, internet RDP is not containment, and Access SSO does not replace sensor isolate.