Ensurepass.com : Ensure you pass the IT Exams
2018 Aug Cisco Official New Released 500-275
100% Free Download! 100% Pass Guaranteed!
Securing Cisco Networks with Sourcefire FireAMP Endpoints
Question No: 11
Custom whitelists are used for which purpose?
-
to specify which files to alert on
-
to specify which files to delete
-
to specify which files to ignore
-
to specify which files to sandbox
Answer: C
Question No: 12
How does application blocking enhance security?
-
It identifies and logs usage.
-
It tracks application abuse.
-
It deletes identified applications.
-
It blocks vulnerable applications from running, until they are patched.
Answer: D
Question No: 13
Which set of actions would you take to create a simple custom detection?
-
Add a SHA-256 value; upload a file to calculate a SHA-256 value; upload a text file that contains SHA-256 values.
-
Upload a packet capture; use a Snort rule; use a ClamAV rule.
-
Manually input the PE header data, the MD-5 hash, and a list of MD-5 hashes.
-
Input the file and file name.
Answer: A
Question No: 14
Advanced custom signatures are written using which type of syntax?
-
Snort signatures
-
Firewall signatures
-
ClamAV signatures
-
bash shell
Answer: C
Question No: 15
What is a valid data source for DFC Windows connector policy configuration?
-
SANS
-
NIST
-
Emerging Threats
-
Custom and Sourcefire
Answer: D
Question No: 16
The Update Window allows you to perform which action?
-
identify which hosts need to be updated
-
email the user to download a new client
-
specify a timeframe when an upgrade can be started and stopped
-
update your cloud instance
Answer: C
Question No: 17
The FireAMP connector supports which proxy type?
-
SOCKS6
-
HTTP_proxy
-
SOCKS5_filename
-
SOCKS7
Answer: B
Question No: 18
What do policies enable you to do?
-
specify a custom whitelist
-
specify group membership
-
specify hosts to include in reports
-
specify which events to view
Answer: A
Question No: 19
What is the default clean disposition cache setting?
A. 3600
B. 604800
C. 10080
D. 1 hour
Answer: B
Question No: 20
Which statement represents a best practice for deploying on Windows servers?
-
You should treat Windows servers like any other host in the deployment.
-
You should obtain the Microsoft TechNet article that describes the proper exclusions for
Windows servers.
-
You should never configure exclusions for Windows servers.
-
You should deploy FireAMP connectors only alongside existing antivirus software on Windows servers.
Answer: B
100% Ensurepass Free Download!
–500-275 PDF
100% Ensurepass Free Guaranteed!
–500-275 Dumps
EnsurePass | ExamCollection | Testking | |
---|---|---|---|
Lowest Price Guarantee | Yes | No | No |
Up-to-Dated | Yes | No | No |
Real Questions | Yes | No | No |
Explanation | Yes | No | No |
PDF VCE | Yes | No | No |
Free VCE Simulator | Yes | No | No |
Instant Download | Yes | No | No |