300-415 · Question #175
An organization requires the use of integrated preventative engines, exploit protection, and the most updated and advanced signature-based antivirus with sandboxing and threat intelligence to stop…
The correct answer is C. Cisco AMP and Threat Grid. Cisco AMP (Advanced Malware Protection) and Threat Grid together provide the comprehensive security features described, including advanced signature-based antivirus, exploit protection, sandboxing, and threat intelligence for preventative security. This integrated solution is…
Question
Options
- ACisco Trust Anchor module
- BURL filtering and Umbrella DNS security
- CCisco AMP and Threat Grid
- DSnort IPS
How the community answered
(38 responses)- A3% (1)
- B8% (3)
- C71% (27)
- D18% (7)
Why each option
Cisco AMP (Advanced Malware Protection) and Threat Grid together provide the comprehensive security features described, including advanced signature-based antivirus, exploit protection, sandboxing, and threat intelligence for preventative security. This integrated solution is designed to stop sophisticated malware and malicious attachments.
Cisco Trust Anchor module (TAM) is a hardware-based security feature that establishes a hardware root of trust for secure boot and device identity, not for malware prevention, sandboxing, or threat intelligence.
URL filtering and Umbrella DNS security primarily focus on blocking access to malicious websites and domains at the DNS layer or HTTP/HTTPS layer, but they do not provide the integrated sandboxing, exploit protection, or advanced signature-based antivirus for analyzing attachments that AMP and Threat Grid offer.
Cisco AMP (Advanced Malware Protection) provides continuous analysis and retrospective security to detect and block malware, while Cisco Threat Grid offers advanced sandboxing capabilities to analyze suspicious files in a safe environment and provide threat intelligence. This combination directly addresses the requirements for integrated preventative engines, exploit protection, advanced signature-based antivirus, sandboxing, and threat intelligence to prevent malicious attachments.
Snort IPS (Intrusion Prevention System) is designed to detect and prevent network intrusions and known exploit attempts based on signatures and behavioral analysis, but it typically does not include the advanced sandboxing, dynamic analysis, or comprehensive threat intelligence for unknown malware and attachments that AMP and Threat Grid provide.
Concept tested: Cisco SD-WAN advanced threat protection solutions
Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/sdwan-xe-gs-book/sdwan-xe-gs-book_chapter_0111.html#id_125028
Topics
Community Discussion
No community discussion yet for this question.