350-701 · Question #28
An engineer is configuring AMP for endpoints and wants to block certain files from executing. Which outbreak control method is used to accomplish this task?
The correct answer is C. application blocking list. To block specific files from executing in AMP for Endpoints, an engineer should use the application blocking list feature.
Question
An engineer is configuring AMP for endpoints and wants to block certain files from executing. Which outbreak control method is used to accomplish this task?
Options
- Adevice flow correlation
- Bsimple detections
- Capplication blocking list
- Dadvanced custom detections
How the community answered
(18 responses)- A6% (1)
- C89% (16)
- D6% (1)
Why each option
To block specific files from executing in AMP for Endpoints, an engineer should use the application blocking list feature.
Device flow correlation is typically related to network visibility and anomaly detection, not direct file execution blocking on endpoints.
Simple detections refer to basic threat identification, not a proactive method for blocking specific files from running.
The application blocking list (or Custom Blocking List) in Cisco AMP for Endpoints allows administrators to specify file hashes or characteristics of applications that should be prevented from executing on protected endpoints. This method provides direct control over what applications are permitted or denied, serving as an effective outbreak control measure.
Advanced custom detections (like custom indicators) are more for identifying complex or unknown threats, not for simply blocking known files from executing.
Concept tested: Cisco AMP file blocking features
Source: https://www.cisco.com/c/en/us/products/collateral/security/advanced-malware-protection-amp-for-endpoints/solution-overview-c22-736040.html
Topics
Community Discussion
No community discussion yet for this question.