Cisco CCNP Security Core (SCOR) 350-701Endpoint Security and Secure Network AccessHard
A security engineer is configuring a Cisco Secure Endpoint (formerly AMP for Endpoints) deployment. The organization has identified a new, highly evasive custom malware strain used in targeted attacks. To ensure maximum protection, the engineer wants to deploy a detection engine that can analyze suspicious files in a cloud-based sandbox environment to identify malicious behavior that might bypass static analysis. Which Cisco Secure Endpoint engine should the engineer prioritize for this capability?
- AOrbital Advanced Search Engine
- BFile Reputation Engine
- CThreat Grid Malware Analysis Engine
- DExploit Prevention Engine
Show answer & explanationAnswer & explanation
Correct answer: C. Threat Grid Malware Analysis Engine
Cisco Secure Endpoint integrates with Cisco Threat Grid, which provides a cloud-based sandbox for dynamic malware analysis. The Threat Grid Malware Analysis Engine executes suspicious files in a safe environment, observes their behavior, and identifies malicious actions, making it ideal for detecting evasive or custom malware that static analysis might miss.
Why the other options are wrong
- A. Orbital is an EDR component for advanced threat hunting and forensic analysis, not sandbox detonation.
- B. File Reputation assigns a trust score based on global prevalence and known threats, not dynamic behavioral analysis.
- D. Exploit Prevention focuses on blocking exploit techniques, not dynamic malware analysis in a sandbox.
Cisco Secure Endpoint Engines: Threat Grid
The Threat Grid Malware Analysis Engine in Cisco Secure Endpoint provides dynamic, cloud-based sandbox analysis of suspicious files to uncover malicious behavior and identify advanced, evasive threats.
- Performs dynamic behavioral analysis.
- Uses a cloud sandbox environment.
- Detects evasive and zero-day malware.
Memory trick: Secure Endpoint is a 'Swiss Army Knife' of engines, each with a sharp purpose.