350-201 · Question #73
Refer to the exhibit. Cisco Advanced Malware Protection installed on an end-user desktop automatically submitted a low prevalence file to the Threat Grid analysis engine. What should be concluded…
The correct answer is D. Threat scores are low and no malicious file activity is detected. Cisco AMP Threat Grid sandbox analysis assigns threat scores based on observed behaviors; low scores across all indicators mean the file showed no malicious activity.
Question
Refer to the exhibit. Cisco Advanced Malware Protection installed on an end-user desktop automatically submitted a low prevalence file to the Threat Grid analysis engine. What should be concluded from this report?
Exhibit
Options
- AThreat scores are high, malicious ransomware has been detected, and files have been modified
- BThreat scores are low, malicious ransomware has been detected, and files have been modified
- CThreat scores are high, malicious activity is detected, but files have not been modified
- DThreat scores are low and no malicious file activity is detected
How the community answered
(18 responses)- A6% (1)
- B6% (1)
- C11% (2)
- D78% (14)
Why each option
Cisco AMP Threat Grid sandbox analysis assigns threat scores based on observed behaviors; low scores across all indicators mean the file showed no malicious activity.
High threat scores would only be assigned if Threat Grid observed clearly malicious behaviors during sandbox execution; the exhibit does not show elevated scores, making this conclusion incorrect.
Low threat scores directly contradict a finding of malicious ransomware, since ransomware activity - file encryption and modification - would produce very high behavioral threat scores, not low ones.
High threat scores with no file modification is internally inconsistent; if scores were high, behavioral indicators such as file system activity would contribute to that score, and the exhibit does not reflect this pattern.
The Threat Grid report in the exhibit displays low threat scores across all behavioral indicators, meaning the sandboxed file did not perform actions associated with malware such as unauthorized file modification, registry changes, network callbacks to command-and-control servers, or process injection. A low score from Threat Grid's scoring engine signifies the file is benign or poses negligible risk based on observed dynamic behavior.
Concept tested: Interpreting Cisco AMP Threat Grid sandbox report scores
Source: https://www.cisco.com/c/en/us/products/security/threat-grid/index.html
Topics
Community Discussion
No community discussion yet for this question.
