nerdexam
Cisco

300-710 · Question #15

Which Cisco Advanced Malware Protection for Endpoints policy is used only for monitoring endpoint actively?

The correct answer is B. audit. Log the detection: In this mode, the identified malicious process is not blocked by MAP, but the detection is logged in the AMP for Endpoints console. (This is Audit mode, where no blocking or quarantine action happens, but the detection is logged.)

Configuration

Question

Which Cisco Advanced Malware Protection for Endpoints policy is used only for monitoring endpoint actively?

Options

  • AWindows domain controller
  • Baudit
  • Ctriage
  • Dprotection

How the community answered

(26 responses)
  • B
    92% (24)
  • C
    4% (1)
  • D
    4% (1)

Explanation

Log the detection: In this mode, the identified malicious process is not blocked by MAP, but the detection is logged in the AMP for Endpoints console. (This is Audit mode, where no blocking or quarantine action happens, but the detection is logged.)

Topics

#Cisco Secure Endpoint#Endpoint Security Policies#AMP for Endpoints#Audit Policy

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice