Which characteristic applies to the endpoint security component of Cisco Threat Defense?
Choose an answer
Tap an option to check your answer.
Correct answer: blocking of fileless malware in real time.
Why this is the answer
Cisco Threat Defense's endpoint security component, Cisco Secure Endpoint (formerly AMP for Endpoints), excels at real-time blocking of advanced threats like fileless malware. Fileless malware operates in memory without writing to disk, making traditional signature-based detection ineffective. Secure Endpoint uses behavioral analysis, machine learning, and exploit prevention to identify and stop such threats. The other options describe different security components or broader capabilities: Detecting and blocking ransomware in email attachments is primarily a function of email security solutions (e.g., Cisco Secure Email). Outbound URL analysis and data transfer controls are typically handled by web security gateways (e.g., Cisco Secure Web Appliance) or next-generation firewalls. User context analysis is a broader capability often integrated across various security components, including identity and access management and security information and event management (SIEM) systems, rather than a sole characteristic of endpoint security.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed