Cisco
300-710 · Question #15
Which Cisco Advanced Malware Protection for Endpoints policy is used only for monitoring endpoint actively?
The correct answer is B. audit. Log the detection: In this mode, the identified malicious process is not blocked by MAP, but the detection is logged in the AMP for Endpoints console. (This is Audit mode, where no blocking or quarantine action happens, but the detection is logged.)
Configuration
Question
Which Cisco Advanced Malware Protection for Endpoints policy is used only for monitoring endpoint actively?
Options
- AWindows domain controller
- Baudit
- Ctriage
- Dprotection
How the community answered
(26 responses)- B92% (24)
- C4% (1)
- D4% (1)
Explanation
Log the detection: In this mode, the identified malicious process is not blocked by MAP, but the detection is logged in the AMP for Endpoints console. (This is Audit mode, where no blocking or quarantine action happens, but the detection is logged.)
Topics
#Cisco Secure Endpoint#Endpoint Security Policies#AMP for Endpoints#Audit Policy
Community Discussion
No community discussion yet for this question.