500-651 · Question #63
Which are two main features of Advanced Malware Protection? (Choose two.)
The correct answer is B. Leverages Global Threat Intelligence to provide zero-day protection C. Threat protection across the entire attack continuum. Advanced Malware Protection (AMP) - Cisco's solution - is built around two pillars: global threat intelligence and continuous, full-lifecycle protection. Option B is correct because AMP integrates with Cisco Talos, one of the largest commercial threat intelligence operations in…
Question
Which are two main features of Advanced Malware Protection? (Choose two.)
Options
- ARapid App Containment
- BLeverages Global Threat Intelligence to provide zero-day protection
- CThreat protection across the entire attack continuum
- DUser and Entity Behavior Analytics
How the community answered
(27 responses)- A7% (2)
- B89% (24)
- D4% (1)
Explanation
Advanced Malware Protection (AMP) - Cisco's solution - is built around two pillars: global threat intelligence and continuous, full-lifecycle protection. Option B is correct because AMP integrates with Cisco Talos, one of the largest commercial threat intelligence operations in the world, enabling it to detect and block zero-day threats using collective data from millions of sensors globally. Option C is correct because AMP is explicitly architected to cover the entire attack continuum - before an attack (prevention), during an attack (detection/blocking), and after an attack (retrospective analysis and remediation), which is a core differentiator from traditional antivirus tools.
A (Rapid App Containment) is a distractor - while containment is a security concept, it's not a named core feature of AMP; it's more associated with EDR or sandbox solutions. D (User and Entity Behavior Analytics / UEBA) is also wrong - UEBA is a distinct technology used in SIEM/UBA platforms like Cisco Stealthwatch to detect insider threats and anomalies, not an AMP feature.
Memory tip: Think "AMP = Global Brain + Full Timeline." The Global Brain is Talos threat intelligence (B), and the Full Timeline is before/during/after attack coverage (C). If an answer choice sounds like a standalone behavior-monitoring product (UEBA) or a containment sandbox, it's not core AMP.
Topics
Community Discussion
No community discussion yet for this question.