300-710 · Question #221
A network administrator is configuring a Cisco AMP public cloud instance and wants to capture infections and polymorphic variants of a threat to help detect families of malware. Which detection…
The correct answer is C. Ethos. To capture infections, polymorphic variants, and detect families of malware within a Cisco AMP public cloud instance, the Ethos detection engine is required.
Question
A network administrator is configuring a Cisco AMP public cloud instance and wants to capture infections and polymorphic variants of a threat to help detect families of malware. Which detection engine meets this requirement?
Options
- ARBAC
- BTetra
- CEthos
- DSpero
How the community answered
(34 responses)- A3% (1)
- B6% (2)
- C91% (31)
Why each option
To capture infections, polymorphic variants, and detect families of malware within a Cisco AMP public cloud instance, the Ethos detection engine is required.
RBAC (Role-Based Access Control) is a security model for managing user permissions, not a malware detection engine.
Tetra is not a recognized Cisco AMP detection engine.
Ethos is a Cisco AMP detection engine that leverages static analysis and genetic algorithms to quickly identify polymorphic variants of known malware and group them into families. This capability is essential for tracking malware evolution and understanding relationships between different threat samples.
Spero is a machine learning engine focused on detecting advanced malware in executables, whereas Ethos is specifically designed for polymorphic variants and malware families.
Concept tested: Cisco AMP Ethos engine for polymorphic malware detection
Source: https://www.cisco.com/c/en/us/products/collateral/security/amp-threat-grid/white-paper-c11-736021.html
Topics
Community Discussion
No community discussion yet for this question.