500-651 · Question #73
How does AMP's device trajectory capabilities help address customer s issues?
The correct answer is C. It isolates suspicious files and runs them in a sandbox environment to determine their authenticity. AMP's Device Trajectory feature sandboxes suspicious files by isolating them in a safe, controlled environment and executing them to observe their behavior - this is how it determines whether a file is genuinely malicious or a false positive, making C correct. Why the…
Question
How does AMP's device trajectory capabilities help address customer s issues?
Options
- AIt determines the scope and cause of an outbreak and tracks suspicious files
- BIt searches for potential threats based on identified activities and behaviors
- CIt isolates suspicious files and runs them in a sandbox environment to determine their authenticity
- DIt analyses the data from suspicious files to provide a new level of threat intelligence
How the community answered
(27 responses)- A7% (2)
- C89% (24)
- D4% (1)
Explanation
AMP's Device Trajectory feature sandboxes suspicious files by isolating them in a safe, controlled environment and executing them to observe their behavior - this is how it determines whether a file is genuinely malicious or a false positive, making C correct.
Why the distractors are wrong:
- A describes File Trajectory (or Outbreak Control), which maps a file's movement across devices to scope and root-cause an infection - a related but distinct AMP capability.
- B describes behavioral detection / Exploit Prevention, which monitors running processes and activities for threat indicators, not isolated sandbox execution.
- D describes Threat Intelligence functions (such as Threat Grid's cloud analysis feeding broader intelligence), not the sandboxing process itself.
Memory tip: Think of "trajectory" as tracking a path - but the device trajectory feature takes it one step further by pulling the suspicious file off that path and into a sandbox "cage" to safely detonate it. Isolate → Execute → Authenticate is the Device Trajectory sandbox loop.
Topics
Community Discussion
No community discussion yet for this question.