700-270 · Question #35
Which security feature can be applied in the "after" stage of the attack continuum'?
The correct answer is B. advanced malware protection. Advanced Malware Protection (AMP) belongs to the "after" stage because it provides retrospective security - it continuously monitors files and behaviors even after they enter the network, allowing it to detect and remediate threats that initially evaded defenses. This makes it un
Question
Which security feature can be applied in the "after" stage of the attack continuum'?
Options
- ANGIPS
- Badvanced malware protection
- CVPNs
- Dstateful firewall installation
How the community answered
(40 responses)- A8% (3)
- B75% (30)
- C15% (6)
- D3% (1)
Explanation
Advanced Malware Protection (AMP) belongs to the "after" stage because it provides retrospective security - it continuously monitors files and behaviors even after they enter the network, allowing it to detect and remediate threats that initially evaded defenses. This makes it uniquely suited for post-breach containment and response, not just prevention.
Why the distractors are wrong:
- A. NGIPS operates during the attack - it inspects traffic in real time to block active intrusions as they occur.
- C. VPNs are a before-stage control - they encrypt tunnels to prevent unauthorized access before an attack begins.
- D. Stateful firewalls are also before-stage - they filter traffic based on connection state as a perimeter defense measure.
Memory tip: Think of AMP as "After Malware Persists" - its key differentiator is retrospective analysis, meaning it can go back and flag files that passed initial inspection once new threat intelligence identifies them as malicious. If a technology can "look back," it lives in the after stage.
Topics
Community Discussion
No community discussion yet for this question.