exam questions

Exam 350-701 All Questions

View all questions & answers for the 350-701 exam

Exam 350-701 topic 1 question 496 discussion

Actual exam question from Cisco's 350-701
Question #: 496
Topic #: 1
[All 350-701 Questions]

An engineer is deploying Cisco Advanced Malware Protection (AMP) for Endpoints and wants to create a policy that prevents users from executing a file named abc123456789.exe without quarantining that file. What type of Outbreak Control list must the SHA-256 hash value for the file be added to in order to accomplish this?

  • A. Advanced Custom Detection
  • B. Simple Custom Detection
  • C. Isolation
  • D. Blocked Application
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
sull3y
Highly Voted 9 months, 1 week ago
The correct answer is D. Blocked Application When deploying Cisco Advanced Malware Protection (AMP) for Endpoints, an engineer can create policies to prevent users from executing certain files without quarantining them. To do this, the SHA-256 hash value for the file must be added to a Blocked Application list in the AMP for Endpoints policy. A Blocked Application list is a type of Outbreak Control list that allows an organization to block specific files or applications, and prevent them from executing on endpoint devices. When a file or application is added to this list, it is blocked and cannot be executed, regardless of its reputation or other characteristics. This can be useful for preventing the execution of known malicious files or applications, or for blocking the execution of files or applications that are known to be vulnerable to exploitation. In this scenario, the SHA-256 hash value for the file named abc123456789.exe must be added to the Blocked Application list in the AMP for Endpoints policy.
upvoted 5 times
...
ddev3737
Most Recent 9 months ago
it is asking about preventing execution of a specific file, not an application. The correct answer is A. Advanced Custom Detection, where the engineer can add the SHA-256 hash value of the file named abc123456789.exe to an Advanced Custom Detection list, this will allow the administrator to prevent execution of the specific file and the file will be quarantined.
upvoted 1 times
CCNP21
9 months ago
Question says "without quarantining the file".
upvoted 3 times
ddev3737
8 months, 3 weeks ago
you are right
upvoted 1 times
...
...
...
ureis
10 months ago
Selected Answer: D
A blocked applications list is composed of files that you do not want to allow users to execute "but do not want to quarantine". https://docs.amp.cisco.com/AMPPrivateCloudConsoleUserGuide-latest.pdf
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago