nerdexam
Cisco

300-415 · Question #175

An organization requires the use of integrated preventative engines, exploit protection, and the most updated and advanced signature-based antivirus with sandboxing and threat intelligence to stop…

The correct answer is C. Cisco AMP and Threat Grid. Cisco AMP (Advanced Malware Protection) and Threat Grid together provide the comprehensive security features described, including advanced signature-based antivirus, exploit protection, sandboxing, and threat intelligence for preventative security. This integrated solution is…

Security and Quality of Service

Question

An organization requires the use of integrated preventative engines, exploit protection, and the most updated and advanced signature-based antivirus with sandboxing and threat intelligence to stop malicious attachments before they reach users and get executed. Which Cisco SD-WAN solution meets the requirements?

Options

  • ACisco Trust Anchor module
  • BURL filtering and Umbrella DNS security
  • CCisco AMP and Threat Grid
  • DSnort IPS

How the community answered

(38 responses)
  • A
    3% (1)
  • B
    8% (3)
  • C
    71% (27)
  • D
    18% (7)

Why each option

Cisco AMP (Advanced Malware Protection) and Threat Grid together provide the comprehensive security features described, including advanced signature-based antivirus, exploit protection, sandboxing, and threat intelligence for preventative security. This integrated solution is designed to stop sophisticated malware and malicious attachments.

ACisco Trust Anchor module

Cisco Trust Anchor module (TAM) is a hardware-based security feature that establishes a hardware root of trust for secure boot and device identity, not for malware prevention, sandboxing, or threat intelligence.

BURL filtering and Umbrella DNS security

URL filtering and Umbrella DNS security primarily focus on blocking access to malicious websites and domains at the DNS layer or HTTP/HTTPS layer, but they do not provide the integrated sandboxing, exploit protection, or advanced signature-based antivirus for analyzing attachments that AMP and Threat Grid offer.

CCisco AMP and Threat GridCorrect

Cisco AMP (Advanced Malware Protection) provides continuous analysis and retrospective security to detect and block malware, while Cisco Threat Grid offers advanced sandboxing capabilities to analyze suspicious files in a safe environment and provide threat intelligence. This combination directly addresses the requirements for integrated preventative engines, exploit protection, advanced signature-based antivirus, sandboxing, and threat intelligence to prevent malicious attachments.

DSnort IPS

Snort IPS (Intrusion Prevention System) is designed to detect and prevent network intrusions and known exploit attempts based on signatures and behavioral analysis, but it typically does not include the advanced sandboxing, dynamic analysis, or comprehensive threat intelligence for unknown malware and attachments that AMP and Threat Grid provide.

Concept tested: Cisco SD-WAN advanced threat protection solutions

Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/sdwan-xe-gs-book/sdwan-xe-gs-book_chapter_0111.html#id_125028

Topics

#AMP#Threat Grid#Malware Prevention#Sandboxing

Community Discussion

No community discussion yet for this question.

Full 300-415 Practice