Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 350-701 Exam - Topic 5 Question 115 Discussion

[Endpoint Protection and Detection]An engineer is configuring AMP for endpoints and wants to block certain files from executing. Which outbreakcontrol method is used to accomplish this task?
C) application blocking list
A) device flow correlation
B) simple detections
D) advanced custom detections

Cisco 350-701 Exam - Topic 5 Question 115 Discussion

Actual exam question for Cisco's 350-701 exam
Question #: 115
Topic #: 5
[All 350-701 Questions]

[Endpoint Protection and Detection]

An engineer is configuring AMP for endpoints and wants to block certain files from executing. Which outbreak

control method is used to accomplish this task?

Show Suggested Answer Hide Answer
Suggested Answer: C

The application blocking list is an outbreak control method that allows the administrator to block certain files from executing on the endpoints based on their SHA values. This can prevent malware from running on the endpoints and causing damage. The other options are not outbreak control methods, but rather different features of AMP for endpoints. Device flow correlation is a network analysis feature that monitors connections and detects malicious activity. Simple detections and advanced custom detections are custom rules that can be created by the administrator to detect and block files based on signatures or other criteria.Reference:

Configure Windows Policy in AMP for Endpoints - Cisco

Prevent, Detect and Respond with Cisco AMP for Endpoints


Contribute your Thoughts:

0/2000 characters
Amie
8 months ago
I've seen C used a lot for this kind of thing.
upvoted 0 times
...
Evangelina
9 months ago
Yeah, that makes sense! Totally agree with you.
upvoted 0 times
...
Veronica
9 months ago
I'm pretty sure it's C, the application blocking list.
upvoted 0 times
...
Xuan
9 months ago
Really? I thought simple detections would cover it.
upvoted 0 times
...
Alberto
9 months ago
Wait, are we sure about that? I thought it could be D too.
upvoted 0 times
...
Tayna
9 months ago
Device flow correlation sounds familiar, but I don't think it relates to blocking files. I might lean towards application blocking list.
upvoted 0 times
...
Serina
10 months ago
I feel like simple detections could be relevant too, but I can't recall if they apply to blocking files directly.
upvoted 0 times
...
Jimmie
10 months ago
I'm not entirely sure, but I remember something about advanced custom detections being used for more complex scenarios.
upvoted 0 times
...
Domingo
10 months ago
I think the application blocking list might be the right answer since it specifically deals with blocking certain files from executing.
upvoted 0 times
...
Lizbeth
10 months ago
I'm a little unsure about this question. I know we need to block certain files, but I'm not sure if the application blocking list is the only way to do that. I might need to review the course material again to be sure.
upvoted 0 times
...
Lynelle
11 months ago
I'm feeling pretty confident about this one. The application blocking list is definitely the right choice to block specific files from executing on the endpoints.
upvoted 0 times
...
Nieves
11 months ago
Okay, let me think this through. We're looking for a way to block certain files from executing, so I think the application blocking list is the best option here. That would allow us to specifically target those files and prevent them from running.
upvoted 0 times
...
Toi
11 months ago
Hmm, I'm a bit confused on this one. I'm not sure if application blocking list is the right answer or if there's another outbreak control method that would be more appropriate.
upvoted 0 times
...
Dana
11 months ago
I'm pretty sure the answer is C. Application blocking list seems like the right method to block certain files from executing.
upvoted 0 times
...

Save Cancel