エンジニアがエンドポイント用のCiscoAdvancedMalware Protection(AMP)を導入しており、ユーザーがabc424952615.exeという名前のファイルを検疫せずに実行できないようにするポリシーを作成したいと考えています。ファイルのSHA.-256ハッシュ値はどのタイプのアウトブレイクコントロールリストである必要がありますか。これを達成するために追加されますか?
正解:D
This is a type of Outbreak Control list that allows the administrator to create a list of files based on their SHA-
256 hash values that will be detected, blocked, and quarantined by the AMP for Endpoints connectors. The Simple Custom Detection list can be applied to a policy and synchronized with the devices that have the AMP connectors installed. This way, the administrator can prevent the execution of specific files without having to quarantine them on the devices.
The other options are incorrect because:
* Advanced Custom Detection is a type of Outbreak Control list that allows the administrator to create custom rules based on file attributes, such as file name, size, path, or parent process. These rules can be used to detect and block files that match certain criteria, but they cannot be used to quarantine them.
* Blocked Application is a type of Outbreak Control list that allows the administrator to create a list of applications based on their SHA-256 hash values that will be blocked from running on the devices that have the AMP connectors installed. However, this list does not detect or quarantine the applications, only prevents them from executing.
* Isolation is a feature of AMP for Endpoints that allows the administrator to isolate a device from the network if it is compromised by malware. This prevents the device from communicating with other devices or the internet, but does not affect the files on the device.
References:
https://www.cisco.com/c/en/us/support/docs/security/amp-endpoints/215176-configure-a-simple-custom- detection-list.html
https://community.cisco.com/t5/endpoint-security/block-list-data-source-in-cisco-amp/td-p/4077205
https://community.cisco.com/t5/security-videos/amp4e-outbreak-control/ba-p/4071894