nerdexam
Cisco

300-710 · Question #173

The administrator notices that there is malware present with an .exe extension and needs to verify if any of the systems on the network are running the executable file. What must be configured within

The correct answer is D. prevalence. To identify which systems on the network are running a specific executable file, such as malware with an .exe extension, the administrator must configure and review the prevalence data within Cisco AMP for Endpoints.

Configuration

Question

The administrator notices that there is malware present with an .exe extension and needs to verify if any of the systems on the network are running the executable file. What must be configured within Cisco AMP for Endpoints to show this data?

Options

  • Avulnerable software
  • Bfile analysis
  • Cthreat root cause
  • Dprevalence

How the community answered

(57 responses)
  • A
    7% (4)
  • B
    16% (9)
  • C
    4% (2)
  • D
    74% (42)

Why each option

To identify which systems on the network are running a specific executable file, such as malware with an .exe extension, the administrator must configure and review the prevalence data within Cisco AMP for Endpoints.

Avulnerable software

'Vulnerable software' reports on known software vulnerabilities, not on the presence or execution of a specific malware file across the network.

Bfile analysis

'File analysis' involves submitting a file to a sandbox for dynamic analysis to confirm if it's malicious, but it does not show its widespread presence across multiple endpoints.

Cthreat root cause

'Threat root cause' provides a detailed forensic timeline for a specific detected threat on a single endpoint, showing its actions, but not its prevalence across the entire network.

DprevalenceCorrect

The 'prevalence' feature in Cisco AMP for Endpoints (now Secure Endpoint) provides visibility into how widely a specific file (identified by its SHA256 hash) has been observed across the protected endpoints, allowing an administrator to quickly see which systems have encountered or are running a particular executable.

Concept tested: Cisco AMP for Endpoints file prevalence reporting

Source: https://docs.cisco.com/en-us/secure-endpoint/user-guide/secure-endpoint-ug.pdf

Topics

#Cisco AMP for Endpoints#Malware detection#File prevalence#Endpoint security monitoring

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice