A Cisco AMP for Endpoints administrator configures a custom detection policy to add specific MD5 signatures. The configuration is created in the simple detection policy section, but it does not work. What is the reason for this failure?
A.
The administrator must upload the file instead of the hash for Cisco AMP to use.
B.
The APK must be uploaded for the application that the detection is intended.
C.
The MD5 hash uploaded to the simple detection policy is in the incorrect format.
D.
Detections for MD5 signatures must be configured in the advanced custom detection policies.
Options under Advanced Detection policy
Some of the Signature types available are:
MD5 Signatures
MD5, PE section based Signatures
File Body-based Signatures
Extended Signature Format (offsets, wildcards, regular expressions)
Logical Signatures
Icon Signatures
I believe D is correct:
In Cisco AMP for Endpoints, MD5 signatures for detections must be configured in the advanced custom detection policies rather than the simple detection policy section. The simple detection policy section is designed for basic detection rules and does not support the use of MD5 signatures.
To add specific MD5 signatures for detections, the administrator needs to create or modify an advanced custom detection policy. In the advanced custom detection policy, there are options to define specific detection criteria, including MD5 signatures, to identify and classify threats.
Option A, uploading the file instead of the hash, is not the reason for the failure. MD5 signatures are typically used to identify files based on their unique hash values rather than uploading the entire file.
The correct answer is D. Detections for MD5 signatures must be configured in the advanced custom detection policies.
Cisco AMP for Endpoints does not support MD5 signatures in simple detection policies. Only SHA-256 hashes are supported in simple detection policies. If an administrator tries to add an MD5 signature to a simple detection policy, the configuration will not work.
To add an MD5 signature to a custom detection policy, the administrator must create an advanced custom detection policy. In the advanced custom detection policy, the administrator can specify the MD5 signature of the file that they want to block.
you cannot enable md5:
from:
https://docs.amp.cisco.com/en/SecureEndpoint/Secure%20Endpoint%20User%20Guide.pdf
You can enter a file’s SHA-256 value to find any devices that observed the file.
!!!You can also drag a file to the Search box!!!
and its SHA-256 value will be computed for you. If you only have a file’s MD5 or SHA-1 value, Search will attempt to match it to a corresponding SHA-256, then search for that SHA-256.
Option B is not relevant to this scenario. Option A is also not correct, as uploading the file itself is not required for MD5-based detections. Option C is incorrect because MD5 hashes are a specific format that should be recognized by the Cisco AMP for Endpoints platform, so this would not be the reason for the failure of the custom detection policy.
Advanced Custom Detections are like traditional antivirus signatures, but they are
written by the user. These signatures can inspect various aspects of a file and have
different signature formats. Some of the available signature formats are:
• MD5 signatures
• MD5, PE section-based signatures
• File body-based signatures
• Extended signature format (offsets, wildcards, regular expressions)
• Logical signatures
• Icon signatures
Advanced custom list
https://docs.amp.cisco.com/en/SecureEndpoint/Secure%20Endpoint%20User%20Guide.pdf
and for Lolz - https://quickview.cloudapps.cisco.com/quickview/bug/CSCvg75304
upvoted 3 times
...
This section is not available anymore. Please use the main Exam Page.350-701 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
nomanlands
Highly Voted 1 year, 10 months agoross123
1 year, 4 months agojerac58653
1 year, 1 month agoF0rtyx40
Most Recent 10 months, 1 week agoums008
10 months, 1 week agommpaing
11 months, 2 weeks agoJessie45785
1 year, 1 month agojerac58653
1 year, 1 month agoachille5
1 year, 2 months agoeryxcs
1 year, 3 months agoEmlia1
1 year, 5 months agoSulSulEi
1 year, 5 months agoWebster21
1 year, 6 months agoJamesy
1 year, 8 months agoSulSulEi
1 year, 5 months agoCCNP21
1 year, 3 months agoMoe1416
1 year, 5 months agosurforlife
1 year, 9 months agoileri_sec
2 years agoSmileebloke
2 years ago