Cisco 500-275 - Securing Cisco Networks with Sourcefire FireAMP Endpoints Exam

Question #11 (Topic: )
Custom whitelists are used for which purpose?
A. to specify which files to alert on B. to specify which files to delete C. to specify which files to ignore D. to specify which files to sandbox
Answer: C
Question #12 (Topic: )
How does application blocking enhance security?
A. It identifies and logs usage. B. It tracks application abuse. C. It deletes identified applications. D. It blocks vulnerable applications from running, until they are patched.
Answer: D
Question #13 (Topic: )
Which set of actions would you take to create a simple custom detection?
A. Add a SHA-256 value; upload a file to calculate a SHA-256 value; upload a text file that contains SHA-256 values. B. Upload a packet capture; use a Snort rule; use a ClamAV rule. C. Manually input the PE header data, the MD-5 hash, and a list of MD-5 hashes. D. Input the file and file name.
Answer: A
Question #14 (Topic: )
Advanced custom signatures are written using which type of syntax?
A. Snort signatures B. Firewall signatures C. ClamAV signatures D. bash shell
Answer: C
Question #15 (Topic: )
What is a valid data source for DFC Windows connector policy configuration?
A. SANS B. NIST C. Emerging Threats D. Custom and Sourcefire
Answer: D
Download Exam
Page: 3 / 10
Total 50 questions