[Endpoint Protection and Detection]
An engineer is configuring AMP for endpoints and wants to block certain files from executing. Which outbreak
control method is used to accomplish this task?
The application blocking list is an outbreak control method that allows the administrator to block certain files from executing on the endpoints based on their SHA values. This can prevent malware from running on the endpoints and causing damage. The other options are not outbreak control methods, but rather different features of AMP for endpoints. Device flow correlation is a network analysis feature that monitors connections and detects malicious activity. Simple detections and advanced custom detections are custom rules that can be created by the administrator to detect and block files based on signatures or other criteria.Reference:
Configure Windows Policy in AMP for Endpoints - Cisco
Prevent, Detect and Respond with Cisco AMP for Endpoints
Amie
8 months agoEvangelina
9 months agoVeronica
9 months agoXuan
9 months agoAlberto
9 months agoTayna
9 months agoSerina
10 months agoJimmie
10 months agoDomingo
10 months agoLizbeth
10 months agoLynelle
11 months agoNieves
11 months agoToi
11 months agoDana
11 months ago