exam questions

Exam 300-210 All Questions

View all questions & answers for the 300-210 exam

Exam 300-210 topic 1 question 11 discussion

Actual exam question from Cisco's 300-210
Question #: 11
Topic #: 1
[All 300-210 Questions]

When using Cisco AMP for Networks, which feature copies a file to the Cisco AMP cloud for analysis?

  • A. Spero analysis
  • B. dynamic analysis
  • C. sandbox analysis
  • D. malware analysis
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Stevens0103
1 year, 2 months ago
Selected Answer: A
"Spero analysis examines structural characteristics such as metadata and header information in executable files. After generating a Spero signature based on this information, if the file is an eligible executable file, the device submits it to the Spero heuristic engine in the AMP cloud. You can also configure rules to submit files for Spero analysis without also submitting them to the AMP cloud." https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Reference_a_wrapper_Chapter_topic_here.html
upvoted 1 times
...
jpapas
1 year, 9 months ago
The answer is B , but we need to point out the tricky wording. Spero Analysis, send a MSEXE structure (small part of the file) to Cisco AMP Cloud. Dynamic Analysis, sens the whole file (copies) to Cisco AMP Treat Grid Cloud So if you assume that Treat-Grid cloud is part of Cisco AMP Cloud Infastricture, you can say B is 100% correct. Another tricky wording is that the Question says "Which feature" and not the correct one "which firepower feature" , making confusion that we need to search in AMP4N features!
upvoted 1 times
...
semi1750
3 years, 1 month ago
• Spero Analysis – Firepower gets the signature of executable files and submits it to the AMP cloud • Local Malware Analysis – Uses a local engine to check for malware. Unknown files or possible risks warrant further inspection • Dynamic Analysis – Sends files to AMP ThreatGrid for further inspection
upvoted 1 times
...
[Removed]
3 years, 1 month ago
Answer is A... https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Reference_a_wrapper_Chapter_topic_here.html#concept_75BFE5A73EFB4216A109922D991FFD34
upvoted 1 times
Pista
2 years, 3 months ago
Spero only send the signature of the file. Correct is Dynamic Analysis.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago