350-701 · Question #593
Which action must be taken in the AMP for Endpoints console to detect specific MD5 signatures on endpoints and then quarantine the files?
The correct answer is A. Configure an advanced custom detection list. To detect specific MD5 signatures and quarantine files on endpoints using AMP for Endpoints, an advanced custom detection list must be configured.
Question
Which action must be taken in the AMP for Endpoints console to detect specific MD5 signatures on endpoints and then quarantine the files?
Options
- AConfigure an advanced custom detection list.
- BConfigure an IP Block & Allow custom detection list
- CConfigure an application custom detection list
- DConfigure a simple custom detection list
How the community answered
(34 responses)- A94% (32)
- B3% (1)
- D3% (1)
Why each option
To detect specific MD5 signatures and quarantine files on endpoints using AMP for Endpoints, an advanced custom detection list must be configured.
In Cisco AMP for Endpoints, an advanced custom detection list allows administrators to define specific file hashes (like MD5) that should be identified as malicious, enabling the system to detect and quarantine those files on endpoints.
An IP Block & Allow custom detection list is used to block or allow network connections based on IP addresses, not to detect file hashes.
An application custom detection list is typically used for managing the execution of specific applications based on their properties, not primarily for detecting arbitrary file hashes.
While a 'simple' custom detection list might exist for basic file blocking, the term 'advanced' specifically implies the capability to use hashes like MD5 for precise file detection and quarantine within AMP for Endpoints.
Concept tested: Cisco AMP for Endpoints custom detections
Source: https://docs.amp.cisco.com/amp_for_endpoints/d_custom-detections.html
Topics
Community Discussion
No community discussion yet for this question.