exam questions

Exam 300-415 All Questions

View all questions & answers for the 300-415 exam

Exam 300-415 topic 1 question 152 discussion

Actual exam question from Cisco's 300-415
Question #: 152
Topic #: 1
[All 300-415 Questions]

A Cisco SD-WAN customer has a requirement to calculate the SHA value for files as they pass through the device to see the returned disposition and determine if the file is good, unknown, or malicious. The customer also wants to perform real-time traffic analysis and generate alerts when threats are detected. Which two
Cisco SD-WAN solutions meet the requirements? (Choose two.)

  • A. Cisco Threat Grid
  • B. Cisco Trust Anchor Module
  • C. Cisco AMP
  • D. Cisco Secure Endpoint
  • E. Cisco Snort IPS
Show Suggested Answer Hide Answer
Suggested Answer: AC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
jawad_khalife
1 month, 1 week ago
Selected Answer: AD
Cisco AMP (formerly) is now Cisco Secure endpoint so A and D
upvoted 1 times
...
Rosh8787
3 months, 1 week ago
CE is the correct answer
upvoted 1 times
...
BECAUSE
9 months ago
Selected Answer: AC
A and C i would say are the answers. https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/security/ios-xe-17/security-book-xe/malware-protection.html
upvoted 1 times
BECAUSE
9 months ago
Sorry C and E after further research
upvoted 1 times
...
...
M_Ryu
1 year, 4 months ago
I think it's C and E Cisco Amp: "File Reputation: The process of using a 256-bit Secure Hash Algorithm (SHA256) signature to compare the file against the Advanced Malware Protection (AMP) cloud server and access its threat intelligence information. The response can be Clean, Unknown, or Malicious." Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/security/ios-xe-17/security-book-xe/malware-protection.html Cisco Snort IPS: "Snort is an open source network IPS that performs real-time traffic analysis and generates alerts when threats are detected on IP networks." Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_data_utd/configuration/xe-16-12/sec-data-utd-xe-16-12-book/snort-ips.pdf
upvoted 1 times
...
colipto
1 year, 5 months ago
Cisco Threat Grid (Option A): Cisco Threat Grid is a cloud-based malware analysis and threat intelligence platform. It allows the customer to calculate the SHA value for files as they pass through the SD-WAN devices. The files are then submitted to Threat Grid for analysis. The platform analyzes files using various sandboxing techniques to determine if the files are good, unknown, or malicious. This provides real-time threat detection and enables the customer to take appropriate actions when threats are detected. Cisco AMP (Advanced Malware Protection) (Option C): Cisco AMP is a comprehensive security solution that provides advanced malware detection, prevention, and response capabilities. It offers file reputation services, file analysis, and sandboxing to identify and block advanced malware and threats. In a Cisco SD-WAN deployment, AMP can be integrated with the SD-WAN devices to perform real-time traffic analysis. This helps in detecting and blocking threats in real-time and generating alerts when malicious activities are identified.
upvoted 2 times
colipto
1 year, 5 months ago
Options B (Cisco Trust Anchor Module), D (Cisco Secure Endpoint), and E (Cisco Snort IPS) do not directly meet the specified requirements for calculating SHA values for files passing through the SD-WAN devices and performing real-time traffic analysis with threat detection and alerts. In summary, Cisco Threat Grid and Cisco AMP are the two Cisco SD-WAN solutions that provide the required capabilities for SHA value calculation and real-time traffic analysis with threat detection and alerting.
upvoted 1 times
...
...
nilkanthy
2 years, 1 month ago
Correct answer is C and E confirmed with Cisco documents.
upvoted 2 times
nilkanthy
2 years, 1 month ago
C for Calculate SHA value for files. E for real time traffic analysis and generate alerts.
upvoted 4 times
...
...
PiyKac
2 years, 2 months ago
CE. https://www.cisco.com/c/en/us/support/docs/routers/xe-sd-wan-routers/217641-configure-sdwan-advanced-malware-protect.html https://content.cisco.com/chapter.sjs?uri=/searchable/chapter/content/en/us/td/docs/ios-xml/ios/sec_data_utd/configuration/xe-16/sec-data-utd-xe-16-6-book/snort-ips.html.xml
upvoted 1 times
...
atiWok
2 years, 2 months ago
correct answer is AC
upvoted 1 times
atiWok
2 years, 2 months ago
https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/security/ios-xe-17/security-book-xe/malware-protection.html
upvoted 1 times
...
...
aafonya
2 years, 2 months ago
Selected Answer: CE
https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_data_utd/configuration/xe-16-12/sec-data-utd-xe-16-12-book/snort-ips.pdf "Snort is an open source network IPS that performs real-time traffic analysis and generates alerts when threats are detected on IP networks. "
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago