To block ransomware at the execution stage and prevent file encryption, which solution should be used?
Choose an answer
Tap an option to check your answer.
Correct answer: Use Cisco AMP deployment with the Malicious Activity Protection engine enabled..
Why this is the answer
Cisco AMP (Advanced Malware Protection) with the Malicious Activity Protection engine is designed to detect and block ransomware at the execution stage. This engine monitors for behaviors characteristic of ransomware, such as file encryption attempts and unauthorized process modifications, and intervenes to prevent damage. While blocking TOR traffic with Firepower can help prevent command and control communication, it doesn't stop ransomware already executing. Firepower with Snort rules for SMB exploitation targets initial infection vectors, not the execution phase of ransomware. Cisco AMP's Exploit Prevention engine focuses on blocking exploits that deliver malware, not the post-exploitation malicious activity like file encryption.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed