Question 1
Incident responders use which policy mode for outbreak control? A.AuditB.ProtectC.TriageD.Emergency
Answer and explanation
Correct answer: C
17 free sample questions228 in the full practice test
Incident responders use which policy mode for outbreak control? A.AuditB.ProtectC.TriageD.Emergency
Correct answer: C
When you are viewing information about a computer, what is displayed? A.the type of antivirus software that is installedB.the internal IP addressC.when the operating system was installedD.the console settings
Correct answer: B
How can customers feed new intelligence such as files and hashes to FireAMP? A.by uploading it to the FTP serverB.from the connectorC.through the management consoleD.by sending it via email
Correct answer: C
What is the first system that is infected with a particular malware called? A.Patient ZeroB.SourceC.InfectorD.Carrier
Correct answer: A
A multinational financial institution is designing a Cisco AMP deployment. They require a solution where endpoints verify file disposition with a local appliance to minimize external traffic, but the appliance must maintain real-time synchronization with global threat intelligence without allowing direct inbound connections from the internet. Which architecture component and configuration best satisfies this requirement?
Correct answer: B
The Private Cloud in Proxy Mode allows the appliance to act as the local authority for endpoints while maintaining an outbound connection to the Cisco public cloud for real-time disposition updates. This satisfies the requirement for local lookup traffic minimization and real-time synchronization without requiring direct inbound internet access.
While analyzing the effectiveness of the Spero engine on Windows endpoints, an engineer notices that machine learning analysis is not occurring for certain files. What is the technical requirement regarding the file structure for the Spero engine to function correctly?
Correct answer: A
The Spero engine relies on machine learning analysis of the structural attributes of Portable Executable (PE) files. If the file is not a PE file (e.g., a PDF or script), Spero cannot generate the necessary feature set for analysis.
A security analyst is investigating a retrospective event. A file initially deemed 'Unknown' and allowed to run was later identified as malicious by the AMP Cloud. Which specific mechanism allows Cisco AMP to retroactively alert the administrator and provide the trajectory of this file?
Correct answer: C
Cisco AMP tracks file activity over time using a unique identifier (SHA-256). When the global intelligence network updates a file's disposition from Unknown to Malicious based on big data analytics, the cloud pushes a retrospective alert to all endpoints that have seen that file, enabling the administrator to view the full trajectory.
Refer to the diagram. An organization has deployed Cisco AMP connectors. Based on the decision flow shown, what happens when the AMP Connector encounters a file that is NOT in its local cache?
Correct answer: B
When a file is accessed and not found in the local cache, the connector calculates the SHA-256 hash and queries the AMP Cloud (or Private Cloud console) for the file's disposition.
Register free to unlock 9 more sample questions