exam questions

Exam 350-701 All Questions

View all questions & answers for the 350-701 exam

Exam 350-701 topic 1 question 265 discussion

Actual exam question from Cisco's 350-701
Question #: 265
Topic #: 1
[All 350-701 Questions]

A Cisco AMP for Endpoints administrator configures a custom detection policy to add specific MD5 signatures. The configuration is created in the simple detection policy section, but it does not work. What is the reason for this failure?

  • A. The administrator must upload the file instead of the hash for Cisco AMP to use.
  • B. The APK must be uploaded for the application that the detection is intended.
  • C. The MD5 hash uploaded to the simple detection policy is in the incorrect format.
  • D. Detections for MD5 signatures must be configured in the advanced custom detection policies.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
nomanlands
Highly Voted 1 year, 10 months ago
Selected Answer: D
D, simple can only do SHA256
upvoted 7 times
ross123
1 year, 4 months ago
Incorrect. See https://docs.amp.cisco.com/en/SecureEndpoint/Secure%20Endpoint%20User%20Guide.pdf, page 36. MD5 IS supported.
upvoted 1 times
jerac58653
1 year, 1 month ago
On page 36 it says is is supported but on advanced, NOT on simple custom detections.
upvoted 4 times
...
...
...
F0rtyx40
Most Recent 10 months, 1 week ago
Selected Answer: D
Options under Advanced Detection policy Some of the Signature types available are: MD5 Signatures MD5, PE section based Signatures File Body-based Signatures Extended Signature Format (offsets, wildcards, regular expressions) Logical Signatures Icon Signatures
upvoted 2 times
...
ums008
10 months, 1 week ago
Selected Answer: D
I believe D is correct: In Cisco AMP for Endpoints, MD5 signatures for detections must be configured in the advanced custom detection policies rather than the simple detection policy section. The simple detection policy section is designed for basic detection rules and does not support the use of MD5 signatures. To add specific MD5 signatures for detections, the administrator needs to create or modify an advanced custom detection policy. In the advanced custom detection policy, there are options to define specific detection criteria, including MD5 signatures, to identify and classify threats. Option A, uploading the file instead of the hash, is not the reason for the failure. MD5 signatures are typically used to identify files based on their unique hash values rather than uploading the entire file.
upvoted 2 times
...
mmpaing
11 months, 2 weeks ago
Selected Answer: D
The correct answer is D. Detections for MD5 signatures must be configured in the advanced custom detection policies. Cisco AMP for Endpoints does not support MD5 signatures in simple detection policies. Only SHA-256 hashes are supported in simple detection policies. If an administrator tries to add an MD5 signature to a simple detection policy, the configuration will not work. To add an MD5 signature to a custom detection policy, the administrator must create an advanced custom detection policy. In the advanced custom detection policy, the administrator can specify the MD5 signature of the file that they want to block.
upvoted 2 times
...
Jessie45785
1 year, 1 month ago
Selected Answer: A
you cannot enable md5: from: https://docs.amp.cisco.com/en/SecureEndpoint/Secure%20Endpoint%20User%20Guide.pdf You can enter a file’s SHA-256 value to find any devices that observed the file. !!!You can also drag a file to the Search box!!! and its SHA-256 value will be computed for you. If you only have a file’s MD5 or SHA-1 value, Search will attempt to match it to a corresponding SHA-256, then search for that SHA-256.
upvoted 1 times
...
jerac58653
1 year, 1 month ago
Selected Answer: D
D https://docs.amp.cisco.com/en/SecureEndpoint/Secure%20Endpoint%20User%20Guide.pdf
upvoted 1 times
...
achille5
1 year, 2 months ago
Selected Answer: D
Option B is not relevant to this scenario. Option A is also not correct, as uploading the file itself is not required for MD5-based detections. Option C is incorrect because MD5 hashes are a specific format that should be recognized by the Cisco AMP for Endpoints platform, so this would not be the reason for the failure of the custom detection policy.
upvoted 1 times
...
eryxcs
1 year, 3 months ago
D is Correct. Absolutely
upvoted 1 times
...
Emlia1
1 year, 5 months ago
Selected Answer: D
D should be the correct one.
upvoted 1 times
...
SulSulEi
1 year, 5 months ago
Selected Answer: D
Check the commebt by Webster21
upvoted 2 times
...
Webster21
1 year, 6 months ago
Selected Answer: D
Advanced Custom Detections are like traditional antivirus signatures, but they are written by the user. These signatures can inspect various aspects of a file and have different signature formats. Some of the available signature formats are: • MD5 signatures • MD5, PE section-based signatures • File body-based signatures • Extended signature format (offsets, wildcards, regular expressions) • Logical signatures • Icon signatures
upvoted 3 times
...
Jamesy
1 year, 8 months ago
C in my opinion. Cheers
upvoted 1 times
SulSulEi
1 year, 5 months ago
I read all of your comments on all questions, and I would advise anyone to ignore any answer given by you. Cheers PS, correct answer is D
upvoted 8 times
CCNP21
1 year, 3 months ago
Lol boom roasted.
upvoted 2 times
...
Moe1416
1 year, 5 months ago
Totally agree!
upvoted 2 times
...
...
...
surforlife
1 year, 9 months ago
no Workaround. MD5 is not supported. Pls comment to Cisco on your test. There is no relevant workaround, must use SHA-256.
upvoted 2 times
...
ileri_sec
2 years ago
Selected Answer: D
It is D.
upvoted 3 times
...
Smileebloke
2 years ago
Advanced custom list https://docs.amp.cisco.com/en/SecureEndpoint/Secure%20Endpoint%20User%20Guide.pdf and for Lolz - https://quickview.cloudapps.cisco.com/quickview/bug/CSCvg75304
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago