nerdexam
Cisco

500-651 · Question #73

How does AMP's device trajectory capabilities help address customer s issues?

The correct answer is C. It isolates suspicious files and runs them in a sandbox environment to determine their authenticity. AMP's Device Trajectory feature sandboxes suspicious files by isolating them in a safe, controlled environment and executing them to observe their behavior - this is how it determines whether a file is genuinely malicious or a false positive, making C correct. Why the…

Endpoint Security

Question

How does AMP's device trajectory capabilities help address customer s issues?

Options

  • AIt determines the scope and cause of an outbreak and tracks suspicious files
  • BIt searches for potential threats based on identified activities and behaviors
  • CIt isolates suspicious files and runs them in a sandbox environment to determine their authenticity
  • DIt analyses the data from suspicious files to provide a new level of threat intelligence

How the community answered

(27 responses)
  • A
    7% (2)
  • C
    89% (24)
  • D
    4% (1)

Explanation

AMP's Device Trajectory feature sandboxes suspicious files by isolating them in a safe, controlled environment and executing them to observe their behavior - this is how it determines whether a file is genuinely malicious or a false positive, making C correct.

Why the distractors are wrong:

  • A describes File Trajectory (or Outbreak Control), which maps a file's movement across devices to scope and root-cause an infection - a related but distinct AMP capability.
  • B describes behavioral detection / Exploit Prevention, which monitors running processes and activities for threat indicators, not isolated sandbox execution.
  • D describes Threat Intelligence functions (such as Threat Grid's cloud analysis feeding broader intelligence), not the sandboxing process itself.

Memory tip: Think of "trajectory" as tracking a path - but the device trajectory feature takes it one step further by pulling the suspicious file off that path and into a sandbox "cage" to safely detonate it. Isolate → Execute → Authenticate is the Device Trajectory sandbox loop.

Topics

#AMP#Sandbox Analysis#Malware Detection#Device Trajectory

Community Discussion

No community discussion yet for this question.

Full 500-651 Practice