# Vision One is an XDR factory. Sensor, inventory, then Workbench / OAT.

Source: https://ai.techclick.in/blog_trendvisionone_session_factory
Markdown: https://ai.techclick.in/blog_trendvisionone_session_factory.md
Publisher: Techclick Infosec Pvt Ltd

Vision One is an XDR factory: sensor → inventory → Workbench / OAT → policy. Official docs.trendmicro.com only.

Quick answer

   Trend Vision One is an  XDR factory . A protection or sensor agent on the host prints  telemetry .  Endpoint Inventory  is the live table — official column  Last agent status reported . If a detection model correlates the events,  Workbench  (Agentic SIEM and XDR → Workbench) prints a ticket with Status, Score, Model name. If only a granular filter fired,  Observed Attack Techniques  lists the event — and official Help says that event  might not  generate a Workbench insight or alert.  Detection Model Management  and  Endpoint Security Policies  ( XDR for Endpoints (EDR) ) are the switches. Success is a live last-seen, then a Workbench ID  or  a named Detection filter, then a named policy — not “the icon is green.”

   Say this out loud

   I do not start with isolate. I ask whether the sensor checked in, which product family Inventory lists, whether Workbench printed an ID or only OAT stamped a filter, and whether the detection model and XDR for Endpoints (EDR) were even on. An OAT row is not a Workbench ID. A Successful isolate task is managing-server receipt, not agent finish.

## 1. Why a green last-seen is not a Workbench ID

 Every other briefing starts with the filename.  vssadmin.exe . “Trend missed it.” That is why students freeze in interviews. The real object is the  telemetry the sensor printed . Workbench, OAT, and policy are only stamps the factory puts on that telemetry before anyone isolates.

 Official factory floor: a protection or sensor agent on the endpoint, Endpoint Inventory as the live list of those agents, then Agentic SIEM and XDR apps that turn events into Observed Attack Techniques rows and — sometimes — Workbench alerts. The console only knows what the agent last reported. Official Inventory column:  Last agent status reported  is the last time the agent connected with Vision One, as a range plus an exact timestamp. Hours old is a dark factory floor. Seconds old is a live worker.

   Hero · the factory floor

   Notice: Vision One does not “miss a file.” It tries to manufacture telemetry, list the host, and stamp a Workbench ID or an OAT filter.

#### What the ticket asked

 “Trend missed vssadmin.” That sentence is a hypothesis. The factory may already have stamped an OAT filter, or printed Workbench  WB-1042 , and you have not opened either.

#### What you prove first

 Identity of the host, then  Last agent status reported , then Workbench ID  or  OAT Detection filter, then the assigned policy / EDR switch. The  evidence desk  is the night-shift version of this order.

   The lie every L1 repeats

   “The tray is green, so Trend is working — we need a wider exception.” A green icon only means a local process is running. If  Last agent status reported  is five days old, or Available Actions says  Sensor disabled , or  XDR for Endpoints (EDR)  is off on the assigned policy, the factory did not print the ticket you think it printed. Widening an exception just stamps more events as invisible.

### Hard words before the runbook

#### Sensor / product family

 Official Security Deployment tiles: Standard Endpoint Protection, Server &amp; Workload Protection, Sensor only, Connected Endpoint Protection. Quote the product, not “Apex is installed.”

#### Sensor disabled vs Unmanaged

  Sensor disabled  = sensor installed but not enabled via sensor or policy settings.  Unmanaged endpoints  = discoverable, no protection or sensor agent. Those are different tickets.

#### Workbench vs OAT

 Workbench is a correlated or standalone  alert  (Insights / All Alerts). OAT is the individual  filter event . Official: OAT events might not generate a Workbench insight or alert.

#### Policy switch

  Detection Model Management  turns models and exceptions on or off.  Endpoint security policy  +  XDR for Endpoints (EDR)  is whether the host can even emit EDR telemetry.

 Official Isolate Endpoint task statuses:  Pending approval ,  Rejected ,  In progress ,  Queued  (agent offline),  Successful ,  Unsuccessful . Official wording: Task status means the managing server received the command — not that the Security Agent finished it. Restore connection is a later task on that isolate record. Use those words in the ticket.

## 2. Mental model — four factory stations

 Hold four parts. Interviews fail when people mix them. Skipping a station is how you isolate a five-day last-seen, or hunt a Workbench ID that a filter was never going to create.

#### 1. The worker is the sensor

     A protection or sensor agent on the host. It sees the endpoint.  Last agent status reported  is the heartbeat.  Sensor disabled  means the worker is installed and the switch is off. A green tray is not this column.

#### 2. The live table is Inventory

      Endpoint Security → Endpoint Inventory . Official: manage, locate, take action. Columns you quote: Endpoint name, Endpoint GUID, product family, last-seen, Isolation status, Endpoint security policy, XDR for Endpoints (EDR).

#### 3. The stamps are Workbench / OAT

      Workbench  = Status, Score, Model name, Workbench ID.  OAT  = Event severity, Detected, Detection filter, Tactic / Technique ID. One is an alert. The other is a filter fire. Do not swap them.

#### 4. The switch is policy

     Detection Model  Status  decides whether filters become Workbench alerts. Endpoint Security Policies decide whether EDR is even on. Empty Workbench after a change window is often this station, not a miss.

   Path · last-seen diamond

   Notice: the diamond is not “did Trend miss it?” It is “did this host print telemetry Vision One could stamp?”

   Flow 1 · one ticket, four stations

       Vision One XDR factory: sensor prints telemetry, inventory proves the host, Workbench or OAT stamps, policy is the switch

- SENSOR-LAB-17 · last-seen 14s · Isolation off 1 Sensor prints telemetry SEP / SWP / sensor disabled ≠ unmanaged dark = no ticket 2 Inventory live host table Last agent status GUID · policy · EDR not a Workbench ID 3 Workbench / OAT alert ID or filter Score · Model name OAT may never be WB empty WB is data 4 Policy model Status XDR for Endpoints exception owner off = expected quiet Workbench stamp ID · Status · Score · Model Insights / All Alerts OAT stamp Detection filter · severity may not create Workbench Isolate is later Response Management task Successful ≠ agent finished XDR Data Explorer sits beside station 3 — it proves the event, it does not replace Inventory or policy. Inventory is the live table. Workbench is the alert. OAT is the filter. Policy is the switch. Isolate is a Response Management task after those exist. Read left → right. Station 1–2 are last-seen plus product. Station 3 is Workbench or OAT. Policy is last before you isolate. Concept: Vision One manufactures telemetry on a sensor and writes alerts or filter events in the cloud. Path: sensor → inventory → Workbench / OAT → policy. Do: never open Isolate Endpoint first. Sensor answers “is this host talking?” Official: Last agent status reported , product family, Available Actions ( Sensor disabled , Unmanaged endpoints , Sensor update recommended , Immediate action required ). Source: Endpoint Inventory + table columns. Workbench / OAT answers “what did the factory stamp?” Official Workbench: Insights for high-priority correlated alerts; All Alerts for root-cause and impact. Official OAT: granular predefined or custom detection filters; those events might not generate a Workbench insight or alert. Source: Workbench + Observed Attack Techniques. Policy answers “was the switch on?” Official: Detection Model Management configures how Vision One detects events in OAT and generates alerts in Workbench. XDR for Endpoints (EDR) is configured in Endpoint Security Policies or a policy override. Source: Detection Model Management + Inventory columns. ## 3. First telemetry vs empty Workbench The first event of a new process has no Workbench ID yet. It walks the factory: sensor observes → Inventory still shows a live last-seen → assigned detection filters stamp OAT → a detection model may correlate a Workbench alert. Later events of the same story ride that filter. That is why “I enabled the model” sometimes does nothing until the next matching event, and why “I isolated the leftover hostname” does nothing if you picked the stale Endpoint GUID. Flow 2 · official factory order (student labels) Vision One first-telemetry factory path versus empty Workbench branches Sensor → last-seen? → Inventory → Workbench or OAT → policy 1 Sensor observe host last-seen? seconds? yes 2 Inventory row live product · Isolation off Workbench alert exists? yes 3a Workbench ID · Score · Model no / stale Stop. Sensor ticket first. Unmanaged · Sensor disabled · last-seen days no 3b Observed Attack Techniques Detection filter · Event severity · may never become Workbench 4 XDR Data Explorer Data source · Log type · hits 5 Policy switch Model Status · EDR on policy 6 Isolate? later Response Management task Official facts students invert 1. OAT events might not generate a Workbench insight or Workbench alert. That is Help, not a miss. 2. Workbench Score = model severity + impact scope. Max 99 on alerts created after 18 Jan 2021. 3. Isolate task Queued means the agent was offline. Successful means the managing server got the command. 4. Detection Model Management is how filters become OAT events and how models generate Workbench alerts. Sources: Observed Attack Techniques · Alert details · Isolate Endpoint task · Detection Model Management Read left → right, then the yellow sensor stop. Decision diamonds = last-seen, then Workbench-exists. Empty Workbench is a branch, not a crash. #1 student trap — OAT is not a miss IR chat: “vssadmin ran, why is Workbench empty?” Official Observed Attack Techniques Help: events listed there might not generate a Workbench insight or alert. Quote Detection filter + Event severity . Next click is Query in XDR Data Explorer or Add to Workbench Insight — not Isolate Endpoint, not “Trend is broken.” ## 4. How to choose the stamps You are not choosing a product. You are choosing which station is allowed to write on the ticket. Choice Use when Do not use when Proof you were right Endpoint Inventory first Anyone asks “is Vision One seeing this?” Last-seen unknown. Tray-icon argument. You already have a Workbench ID and last-seen was proved this shift. Last agent status reported + product family + Sensor disabled vs Unmanaged Workbench All Alerts Ticket already names an ID, or you need Status / Score / Model name. Inventory last-seen is days old. Isolate will sit Queued. Workbench ID, Status (Open / In progress / Closed), Score, Model name Observed Attack Techniques Host looks dirty, Workbench is empty, last-seen is live. You treat the filter row as a Sev-1 Workbench case and page SOC. Detection filter + Event severity + Technique ID. Official: may never become Workbench. XDR Data Explorer You have a Highlight or Event UUID and need the event, not the title. You use Search as a substitute for last-seen or for a policy switch. Data source / processor + Log type (Detection / Telemetry / System) + hits Detection Model on You want matching filters to be able to generate Workbench alerts. You disable the Workbench app because Finance is angry about daily noise. Model Status + applicable products. Exceptions have an owner and an expiry. XDR for Endpoints (EDR) on The assigned Endpoint security policy should emit EDR telemetry. You hunt a missing Workbench ID after a change window turned EDR off. Inventory columns: Endpoint security policy + XDR for Endpoints (EDR) Isolate Endpoint Last-seen is live, Workbench or OAT+Search proved staging, owner accepts the blast radius. Unmanaged host, Sensor disabled, last-seen five days, or CREM-only High tile. Response Management Action = Isolate Endpoint + task status. Restore is a second task. Workbench Score is not a vibe. Official Alert details: Vision One calculates the score from the severity of the matched detection model and the impact scope. Starting 18 January 2021 the maximum is 99, and that model only applies to new alerts. Quote Score next to Model name. Source: Alert details. ## 5. Runbook Side A → B → C Lab values only. Hostname SENSOR-LAB-17 , Workbench WB-1042 , product Standard Endpoint Protection, policy Lab-Standard-EDR , last-seen 14s, Isolation off. Nothing here is a live tenant. ### Side A — sensor and inventory (building the factory floor) Primary source: Endpoint Inventory + table columns . #### Open Endpoint Inventory on the failing name Path: Endpoint Security → Endpoint Inventory . Filter Endpoint name SENSOR-LAB-17 . If two rows share a name, quote Endpoint GUID . Do not trust a colleague’s row from a different hostname.

- #### Read Available Actions, not the wallpaper Official tiles: Immediate action required, Unmanaged endpoints, Sensor disabled, Sensor update recommended. Sensor disabled = installed but not enabled via sensor or policy settings. Unmanaged = no protection or sensor agent. Those are different tickets. Sensor-only endpoints are not in endpoint groups — use Add filters.

- #### Quote the live columns Copy Last agent status reported (range + exact timestamp), product family (Standard Endpoint Protection / Server & Workload / Sensor only / Connected Endpoint Protection), Isolation status , Endpoint security policy , XDR for Endpoints (EDR) . Lab: 14s, SEP, Isolated = No, Lab-Standard-EDR, EDR enabled.

     https://portal.lab.visionone.example / endpoint-security / endpoint-inventory / SENSOR-LAB-17

     Training mock · not live

       Endpoint Security → Endpoint Inventory → SENSOR-LAB-17

### Endpoint SENSOR-LAB-17

          Endpoint name  SENSOR-LAB-17

          Endpoint GUID  EP-LAB-17-0001

          Security Deployment  Standard Endpoint Protection

          Last agent status reported   14s  · 2026-08-16 10:41:08Z

          Isolation status  Isolated = No

          XDR for Endpoints (EDR)  Enabled

        Endpoint security policy  Lab-Standard-EDR

       Available Actions for this host: none of Unmanaged · Sensor disabled · Sensor update recommended. Isolation off means isolate is still a decision.

    Source:  Endpoint Inventory + table columns. Dummy lab host only. Next click: Workbench if you have an ID; OAT if Workbench is empty. Do not isolate from this screen until Side B exists.

### Side B — Workbench and OAT (printing the ticket)

 Primary source:  Workbench  +  Observed Attack Techniques  +  Alert details .

- #### Open the alert before you tune Path: Agentic SIEM and XDR → Workbench . Insights is the high-priority correlated view. All Alerts is the full list for root-cause and impact. Quote Workbench ID, Status, Score, Model name, Impact scope, Data source / processor. Lab: WB-1042 , Open, High / Score 81, Possible ransomware staging, 1 endpoint, Standard Endpoint Protection.

- #### If Workbench is empty, open OAT — do not declare a miss Path: Agentic SIEM and XDR → Observed Attack Techniques . Filter Event severity + last Detected, then Add filter on Detection filter / Technique ID / endpoint name. Official: these events might not generate a Workbench insight or alert. Lab filter: Volume shadow copy deletion.

- #### Prove the event in XDR Data Explorer Path: Agentic SIEM and XDR → XDR Data Explorer . Select Data source / processor and Log type (Detection events, then Telemetry events if Detection is empty). Investigate host = SENSOR-LAB-17 , or Search Event UUID from Highlights. Confirm query fields in the tenant. Saved queries store the string, not the results (cap 200).

     https://portal.lab.visionone.example / siem-xdr / workbench / all-alerts / WB-1042

     Training mock · not live

       Agentic SIEM and XDR → Workbench → All Alerts → WB-1042

### Alert WB-1042

         Summary  Highlights  Timeline  Observable Graph

          Workbench ID  WB-1042

          Status   Open

          Score   81  · model + impact scope

          Model name  Possible ransomware staging

          Impact scope  1 endpoint · SENSOR-LAB-17

          Data source / processor  Standard Endpoint Protection

        Highlights · Detection filter  Volume shadow copy deletion · Technique T1490

       Findings stay “—” until you set True positive / False positive / Benign true positive / Noteworthy / Other findings. Change Status only after these identity fields are on the ticket.

    Source:  Workbench + Alert details. Lab values only. Next click: Search Event UUID or Investigate host in XDR Data Explorer. Do not open CREM from this screen.

   Dummy lab · Techclick simulator key trendvisionone · not a live tenant
 V1-LAB &gt; show inventory SENSOR-LAB-17
endpoint=SENSOR-LAB-17 guid=EP-LAB-17-0001
product='Standard Endpoint Protection'
last_agent_status_reported=14s isolation=off
policy=Lab-Standard-EDR xdr_for_endpoints=enabled

V1-LAB &gt; show workbench WB-1042
id=WB-1042 status=Open score=81
model='Possible ransomware staging' endpoints=1
data_source='Standard Endpoint Protection'

V1-LAB &gt; show oat endpoint=SENSOR-LAB-17
filter='Volume shadow copy deletion' severity=High
technique=T1490 detected=10:41Z
note='OAT events might not generate a Workbench alert'

### Side C — policy, then isolate only if Side A + B exist

 Primary source:  Detection Model Management  +  Isolate Endpoint task .

- #### Read the switches before you hunt a missing ID Path: Agentic SIEM and XDR → Detection Model Management . Tabs: Detection Models, Custom Models, Custom Filters, Exceptions. Official: this app configures how Vision One detects events in OAT and generates alerts in Workbench. Quote model Status, severity, applicable products.

- #### Read EDR on the assigned policy From the Inventory row: Endpoint security policy + XDR for Endpoints (EDR) . Overrides live under Endpoint security policy on the selected endpoints. If EDR is disabled, empty Workbench is expected. Do not invent an isolate to “make Trend see it.”

- #### Tune with owner + expiry — do not disable Workbench Daily noise is Exceptions (Detection Model Management → Exceptions), scoped, with an owner and an expiry. Do not disable the Workbench app. Do not delete the model so Finance can work.

- #### Isolate is a Response Management task Context menu → Isolate Endpoint → Description → Create. Monitor under Workflow and Automation → Response Management . Statuses: Pending approval, Rejected, In progress, Queued (agent offline), Successful, Unsuccessful. Official: Successful is managing-server receipt, not agent finish. Restore connection is a later task. Critical endpoints can be excluded; isolated infra can get inbound/outbound exceptions.

     https://portal.lab.visionone.example / siem-xdr / detection-model-management

     Training mock · not live

       Agentic SIEM and XDR → Detection Model Management → Detection Models

### Possible ransomware staging

         Detection Models  Custom Models  Custom Filters  Exceptions

          Status   Enabled

          Model severity  High

          Applicable products  Standard Endpoint Protection

          Generates  OAT events · Workbench alerts

        XDR for Endpoints (EDR) on Lab-Standard-EDR  Enabled · no override on SENSOR-LAB-17

         Add exception (owner + expiry)
         Keep model on

       If Status were off, or EDR disabled on the policy, empty Workbench is the factory working as configured — not a miss.

    Source:  Detection Model Management + Isolate Endpoint task. Dummy lab only. Next: if you isolate, open Response Management and plan Restore connection.

   Green success on this runbook

   Inventory:  SENSOR-LAB-17 , last-seen 14s, SEP, Isolation off, policy Lab-Standard-EDR, EDR enabled. Workbench:  WB-1042  Open, Score 81, Model name Possible ransomware staging —  or  OAT Detection filter named with Event severity. Search: Data source + Log type + hits. Isolate only after those exist; task status quoted as managing-server receipt. Restore plan named.

## 6. Runtime — isolate, restore, old filters

 Once sensors are connected, every night-shift ticket is the same walk. Do not invent a new order because a tile is red.

   Proof · last-seen then the stamp

   Notice: juniors stare at a High tile. Seniors stare at Last agent status reported, then Workbench ID or Detection filter.

   Flow 3 · runtime IR path

       Runtime path from sensor last-seen to restore

- 1 Sensor last-seen 2 Inventory product · EDR 3 WB / OAT ID or filter 4 Policy model · EDR 5 Isolate? task status Restore Keep Workbench or the OAT row open until isolate + hash block + restore plan exist. After go-live this is the only order. Policy is station 4, not station 1. Restore is a second task, not a reboot. Later events of the same filter ride the existing OAT story. Adding the event to a Workbench Insight (official OAT action) updates impact scope and highlighted object — it does not invent a sensor that was never talking. Hide Value on an OAT Detection filter is temporary. Official: you cannot save the Hidden objects list; leaving Observed Attack Techniques resets it. That is not an exception. Exceptions live under Detection Model Management and need an owner. If you clicked View Event from an old Workbench ID and OAT is empty, do not declare the filter dead on this page — confirm retention and the date in your tenant Help before you tune. Night-shift field map: evidence desk . Network, email, and endpoint degrade independently. A delayed network source is a caveat on the story, not a reason to stop IR when the endpoint sensor is healthy and Search already has the hash. Sensor health is not a message verdict: a green Cloud Email sensor does not make that one document clean. ## 7. Traps + factory proof Symptom Looks like Actually First move Empty Workbench, host looks dirty Trend missed it OAT-only filter, or model / EDR off OAT Detection filter, then policy Status Tray green, last-seen 5 days Sensor is fine Dark factory floor Inventory Last agent status reported Sensor disabled Laptop is off Installed, switch off via sensor or policy Available Actions — not a Workbench hunt Unmanaged Isolate from context menu No protection or sensor agent Deploy an agent. Do not isolate. Isolate Successful Host is off the wire Managing server received the command Quote official task-status wording; restore is later Isolate Queued Platform bug Agent offline — last-seen already told you Sensor ticket first EDR disabled after change window Silent miss Switch off — expected quiet Endpoint security policy + EDR column Daily Workbench noise Disable Workbench Exception without owner Scoped exception, owner + expiry High CREM tile, no Workbench Page SOC Exposure queue, not this factory stamp Do not isolate from CREM-only OAT Hide Value Permanent tune List resets when you leave OAT Detection Model exception if it must persist Proof checklist — the factory printed a real ticket Endpoint Inventory hostname matches the ticket (Endpoint GUID if two hosts share a name).

- Last agent status reported is seconds-to-minutes, not days. Product family quoted.

- Available Actions is not Sensor disabled / Unmanaged for this host.

- Either Workbench ID + Status + Score + Model name, or OAT Detection filter + Event severity (and you said out loud that OAT might never become Workbench).

- XDR Data Explorer: Data source / processor + Log type + hits in the UTC window — if you needed the event, not the title.

- Policy: Detection Model Status and/or XDR for Endpoints (EDR) on the assigned Endpoint security policy.

- If you isolated: Response Management Action = Isolate Endpoint + task status. Restore connection named as a second task.

- If you tuned: exception owner + expiry. Workbench app still on.

   Interview close you can steal

   Vision One is an XDR factory. The sensor prints telemetry. Endpoint Inventory proves the host with Last agent status reported. Workbench stamps a correlated alert — or Observed Attack Techniques stamps a filter that official Help says might never become a Workbench ID. Detection Model Management and XDR for Endpoints (EDR) are the switches. I isolate only after those stations exist, and I treat a Successful task as managing-server receipt, not agent finish.

 Next: run the five night-shift tickets on the  evidence desk . Practice console:  Vision One hub simulator  (key  trendvisionone ).

## Knowledge check

   Six judgment questions. Map each miss back to the section named in the reason.

       Q1
       What is Trend Vision One, as a factory, in one line?

           A CREM scoring engine that pages SOC whenever a tile is High
           An XDR factory: sensor prints telemetry, inventory proves the host, Workbench or OAT stamps the ticket, policy is the switch
           Three separate products — Apex One, Workbench, and Isolate — cabled in series
           A tray icon that proves EDR is on

       Correct:  b . Sensor → inventory → Workbench / OAT → policy. Re-read Quick answer and Mental model.

       Q2
       WFH user: “Is Vision One even seeing this laptop?” You have not opened Workbench. First proof?

           Endpoint Inventory — quote Last agent status reported + product family (and Sensor disabled vs Unmanaged if sick)
           Isolate Endpoint from the context menu so telemetry starts
           Disable the detection model so Finance can work
           Open CREM and page SOC for the High tile

       Correct:  a . Official Inventory path and columns. There is no Workbench ID to chase until the sensor is talking. Re-read Side A and Why a green last-seen is not a Workbench ID.

       Q3
       Last-seen is 14 seconds. Workbench is empty. IR chat says the host looks dirty. First stamp?

           Declare a Sev-1 miss and isolate every matching hostname
           Change Status on a Workbench ID you do not have
           Observed Attack Techniques — Event severity + Detection filter (official: OAT might not generate a Workbench insight or alert)
           Hide Value on every filter and call it a permanent exception

       Correct:  c . Official OAT Help. A filter fire is not a Workbench ID. Hide Value resets when you leave OAT. Re-read First telemetry vs empty Workbench and Side B.

       Q4
       Response Management shows Isolate Endpoint = Successful on SENSOR-LAB-17. What is that sentence allowed to mean?

           The laptop is powered off, so isolation completed locally
           Restore connection already ran
           CREM endpoint-risk dropped to Low
           The managing server received and executed the command — official Help says that does not necessarily mean the Security Agent finished it

       Correct:  d . Isolate Endpoint task Help. Queued = agent offline. Restore is a later task. Re-read Side C and the traps table.

       Q5
       XDR for Endpoints (EDR) is disabled on the assigned Endpoint security policy. Empty Workbench is expected. What do you quote?

           Disable the Workbench app so the queue stays empty
           Endpoint security policy + XDR for Endpoints (EDR) disabled — do not hunt a missing Workbench ID first; the switch is off
           Mark a fictional alert Closed — False Positive
           Isolate from CREM because the tile is High

       Correct:  b . Official Inventory columns plus Detection Model Status when the named model is off. Re-read How to choose and Side C.

       Q6
       Endpoint Inventory shows  Sensor disabled  for a discoverable laptop. What does that mean?

           The laptop is powered off
           Isolation already ran
           The Vision One sensor is installed but not enabled via sensor or policy settings
           Workbench is empty, so the sensor paused itself

       Correct:  c . Official Available Actions wording. Unmanaged is the other trap — no agent at all. Re-read Hard words and Side A.

       Check answers
       Reset

## Sources

- Trend Vision One Online Help — platform map: Agentic SIEM & XDR (Workbench, XDR Data Explorer, Observed Attack Techniques, Detection Model Management), Endpoint Security

- Endpoint Inventory — Available Actions (Immediate action required, Unmanaged endpoints, Sensor disabled, Sensor update recommended); Security Deployment product families; Isolate Endpoint / Restore connection; sensor-only endpoints are not in groups

- Endpoint Inventory table columns — Last agent status reported , Isolation status , Endpoint security policy , XDR for Endpoints (EDR) , Endpoint GUID, Endpoint name

- Workbench — Agentic SIEM and XDR → Workbench; Insights vs All Alerts

- Alert details — Status (Open / In progress / Closed), Score (model severity + impact scope; max 99 after 18 Jan 2021), Workbench ID, Model name, Impact scope, Data source / processor, Findings, Highlights

- Observed Attack Techniques — Event severity, Detected, Detection filter, Tactic / Technique ID; OAT events might not generate Workbench; Query in XDR Data Explorer; Add to Workbench Insight; Hide Value is not saved

- XDR Data Explorer — Agentic SIEM and XDR → XDR Data Explorer; Data source / processor; Log type (Detection / Telemetry / System events); Investigate host; saved queries store the string, not results (cap 200)

- Detection Model Management — configures OAT events and Workbench alerts; tabs Detection Models, Custom Models, Custom Filters, Exceptions

- Detection model / filter exceptions — Detection Model Management → Exceptions

- Endpoint security policy overrides — per-endpoint overrides from Inventory

- Isolate Endpoint task — context menu; Response Management statuses; Task status is managing-server receipt; Restore connection is a later task

- Restore Connection task

 Related:  Blog 2 · Evidence desk — first tool + proof field  ·  Trend Vision One interview hub  ·  Dummy lab

 Dummy lab data only. Confirm live syntax, permissions and change-control on the production release before you type on a real tenant.

---
Cite this Techclick lesson with the source URL. Do not invent fees, batch dates, or job guarantees.
Browse all lessons: https://ai.techclick.in/blogs
AI index: https://ai.techclick.in/llms.txt
