nerdexam
Cisco

300-725 · Question #15

What is the purpose of using AMP file analysis on a Cisco WSA to continuously evaluate emerging threats?

The correct answer is C. to notify you of files that are determined to be threats after they have entered your network. AMP (Advanced Malware Protection) on the Cisco WSA includes a retrospective analysis capability. When a file is first downloaded, it may appear benign and be allowed into the network. However, AMP continuously re-evaluates files even after they have passed the initial…

Cisco WSA DVS and AMP

Question

What is the purpose of using AMP file analysis on a Cisco WSA to continuously evaluate emerging threats?

Options

  • Ato take appropriate action on new files that enter the network
  • Bto remove files from quarantine by stopping their retention period
  • Cto notify you of files that are determined to be threats after they have entered your network
  • Dto send all files downloaded through the Cisco WSA to the AMP cloud

How the community answered

(23 responses)
  • A
    4% (1)
  • B
    9% (2)
  • C
    87% (20)

Explanation

AMP (Advanced Malware Protection) on the Cisco WSA includes a retrospective analysis capability. When a file is first downloaded, it may appear benign and be allowed into the network. However, AMP continuously re-evaluates files even after they have passed the initial inspection. If a file's disposition changes from clean to malicious based on updated threat intelligence from the AMP cloud, the WSA will generate a retrospective alert notifying administrators that a previously admitted file is now identified as a threat. This is distinct from blocking new files at entry (A), managing quarantine (B), or sending all files to the cloud (D, which describes file submission, not the continuous evaluation purpose).

Topics

#Cisco AMP#WSA#Retrospective analysis#Malware detection

Community Discussion

No community discussion yet for this question.

Full 300-725 Practice