exam questions

Exam 300-415 All Questions

View all questions & answers for the 300-415 exam

Exam 300-415 topic 1 question 152 discussion

Actual exam question from Cisco's 300-415
Question #: 152
Topic #: 1
[All 300-415 Questions]

A Cisco SD-WAN customer has a requirement to calculate the SHA value for files as they pass through the device to see the returned disposition and determine if the file is good, unknown, or malicious. The customer also wants to perform real-time traffic analysis and generate alerts when threats are detected. Which two
Cisco SD-WAN solutions meet the requirements? (Choose two.)

  • A. Cisco Threat Grid
  • B. Cisco Trust Anchor Module
  • C. Cisco AMP
  • D. Cisco Secure Endpoint
  • E. Cisco Snort IPS
Show Suggested Answer Hide Answer
Suggested Answer: AC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
jawad_khalife
2 days, 15 hours ago
Selected Answer: AD
Cisco AMP (formerly) is now Cisco Secure endpoint so A and D
upvoted 1 times
...
Rosh8787
1 month, 4 weeks ago
CE is the correct answer
upvoted 1 times
...
BECAUSE
7 months, 3 weeks ago
Selected Answer: AC
A and C i would say are the answers. https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/security/ios-xe-17/security-book-xe/malware-protection.html
upvoted 1 times
BECAUSE
7 months, 3 weeks ago
Sorry C and E after further research
upvoted 1 times
...
...
M_Ryu
1 year, 3 months ago
I think it's C and E Cisco Amp: "File Reputation: The process of using a 256-bit Secure Hash Algorithm (SHA256) signature to compare the file against the Advanced Malware Protection (AMP) cloud server and access its threat intelligence information. The response can be Clean, Unknown, or Malicious." Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/security/ios-xe-17/security-book-xe/malware-protection.html Cisco Snort IPS: "Snort is an open source network IPS that performs real-time traffic analysis and generates alerts when threats are detected on IP networks." Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_data_utd/configuration/xe-16-12/sec-data-utd-xe-16-12-book/snort-ips.pdf
upvoted 1 times
...
colipto
1 year, 4 months ago
Cisco Threat Grid (Option A): Cisco Threat Grid is a cloud-based malware analysis and threat intelligence platform. It allows the customer to calculate the SHA value for files as they pass through the SD-WAN devices. The files are then submitted to Threat Grid for analysis. The platform analyzes files using various sandboxing techniques to determine if the files are good, unknown, or malicious. This provides real-time threat detection and enables the customer to take appropriate actions when threats are detected. Cisco AMP (Advanced Malware Protection) (Option C): Cisco AMP is a comprehensive security solution that provides advanced malware detection, prevention, and response capabilities. It offers file reputation services, file analysis, and sandboxing to identify and block advanced malware and threats. In a Cisco SD-WAN deployment, AMP can be integrated with the SD-WAN devices to perform real-time traffic analysis. This helps in detecting and blocking threats in real-time and generating alerts when malicious activities are identified.
upvoted 2 times
colipto
1 year, 4 months ago
Options B (Cisco Trust Anchor Module), D (Cisco Secure Endpoint), and E (Cisco Snort IPS) do not directly meet the specified requirements for calculating SHA values for files passing through the SD-WAN devices and performing real-time traffic analysis with threat detection and alerts. In summary, Cisco Threat Grid and Cisco AMP are the two Cisco SD-WAN solutions that provide the required capabilities for SHA value calculation and real-time traffic analysis with threat detection and alerting.
upvoted 1 times
...
...
nilkanthy
2 years ago
Correct answer is C and E confirmed with Cisco documents.
upvoted 2 times
nilkanthy
2 years ago
C for Calculate SHA value for files. E for real time traffic analysis and generate alerts.
upvoted 4 times
...
...
PiyKac
2 years ago
CE. https://www.cisco.com/c/en/us/support/docs/routers/xe-sd-wan-routers/217641-configure-sdwan-advanced-malware-protect.html https://content.cisco.com/chapter.sjs?uri=/searchable/chapter/content/en/us/td/docs/ios-xml/ios/sec_data_utd/configuration/xe-16/sec-data-utd-xe-16-6-book/snort-ips.html.xml
upvoted 1 times
...
atiWok
2 years, 1 month ago
correct answer is AC
upvoted 1 times
atiWok
2 years, 1 month ago
https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/security/ios-xe-17/security-book-xe/malware-protection.html
upvoted 1 times
...
...
aafonya
2 years, 1 month ago
Selected Answer: CE
https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_data_utd/configuration/xe-16-12/sec-data-utd-xe-16-12-book/snort-ips.pdf "Snort is an open source network IPS that performs real-time traffic analysis and generates alerts when threats are detected on IP networks. "
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago