nerdexam
Cisco

300-725 · Question #39

Which method is used by AMP against zero-day and targeted file-based attacks?

The correct answer is D. obtaining the reputation of known files. Cisco AMP (Advanced Malware Protection) uses file reputation as its primary detection method. When a file is encountered, AMP calculates its SHA-256 hash and queries Cisco's cloud-based threat intelligence to obtain the file's known reputation (clean, malicious, or unknown)…

Cisco WSA DVS and AMP

Question

Which method is used by AMP against zero-day and targeted file-based attacks?

Options

  • Aanalyzing behavior of all files that are not yet known to the reputation service
  • Bperiodically evaluating emerging threats as new information becomes available
  • Cimplementing security group tags
  • Dobtaining the reputation of known files

How the community answered

(33 responses)
  • B
    3% (1)
  • C
    6% (2)
  • D
    91% (30)

Explanation

Cisco AMP (Advanced Malware Protection) uses file reputation as its primary detection method. When a file is encountered, AMP calculates its SHA-256 hash and queries Cisco's cloud-based threat intelligence to obtain the file's known reputation (clean, malicious, or unknown). This reputation lookup is AMP's foundational defense layer - even against targeted attacks - because it instantly identifies files already associated with known malware families or threat actors. Additional methods like behavioral analysis and sandboxing apply to files not yet known to the reputation service, but obtaining the reputation of known files is the core method described.

Topics

#AMP#File Reputation#Zero-day protection#Malware Defense

Community Discussion

No community discussion yet for this question.

Full 300-725 Practice