exam questions

Exam 350-401 All Questions

View all questions & answers for the 350-401 exam

Exam 350-401 topic 1 question 270 discussion

Actual exam question from Cisco's 350-401
Question #: 270
Topic #: 1
[All 350-401 Questions]

An engineer must protect their company against ransomware attacks.
Which solution allows the engineer to block the execution stage and prevent file encryption?

  • A. Use Cisco Firepower and block traffic to TOR networks.
  • B. Use Cisco AMP deployment with the Malicious Activity Protection engine enabled.
  • C. Use Cisco Firepower with Intrusion Policy and snort rules blocking SMB exploitation.
  • D. Use Cisco AMP deployment with the Exploit Prevention engine enabled.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
cvndani
Highly Voted 3 years ago
AMP with MAP :)
upvoted 20 times
...
Kakat
Highly Voted 4 years, 1 month ago
B is correct: https://www.cisco.com/c/dam/en/us/products/collateral/security/amp-for-endpoints/white-paper-c11-740980.pdf Malicious Activity Protection provides run-time detection and blocking of abnormal behavior of a running program on the endpoint (for example,behaviors associated with ransomware).
upvoted 7 times
...
anonymous1966
Most Recent 3 years, 5 months ago
See Malicious activity protection at https://www.cisco-parts.ru/upload/iblock/632/cisco-advanced-malware-protection.pdf
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...