300-710 · Question #173
The administrator notices that there is malware present with an .exe extension and needs to verify if any of the systems on the network are running the executable file. What must be configured within
The correct answer is D. prevalence. To identify which systems on the network are running a specific executable file, such as malware with an .exe extension, the administrator must configure and review the prevalence data within Cisco AMP for Endpoints.
Question
The administrator notices that there is malware present with an .exe extension and needs to verify if any of the systems on the network are running the executable file. What must be configured within Cisco AMP for Endpoints to show this data?
Options
- Avulnerable software
- Bfile analysis
- Cthreat root cause
- Dprevalence
How the community answered
(57 responses)- A7% (4)
- B16% (9)
- C4% (2)
- D74% (42)
Why each option
To identify which systems on the network are running a specific executable file, such as malware with an .exe extension, the administrator must configure and review the prevalence data within Cisco AMP for Endpoints.
'Vulnerable software' reports on known software vulnerabilities, not on the presence or execution of a specific malware file across the network.
'File analysis' involves submitting a file to a sandbox for dynamic analysis to confirm if it's malicious, but it does not show its widespread presence across multiple endpoints.
'Threat root cause' provides a detailed forensic timeline for a specific detected threat on a single endpoint, showing its actions, but not its prevalence across the entire network.
The 'prevalence' feature in Cisco AMP for Endpoints (now Secure Endpoint) provides visibility into how widely a specific file (identified by its SHA256 hash) has been observed across the protected endpoints, allowing an administrator to quickly see which systems have encountered or are running a particular executable.
Concept tested: Cisco AMP for Endpoints file prevalence reporting
Source: https://docs.cisco.com/en-us/secure-endpoint/user-guide/secure-endpoint-ug.pdf
Topics
Community Discussion
No community discussion yet for this question.