🔥 3-day streak
Cisco CCNA Cybersecurity (200-201 CCNACBR)87 / 145
Question 87 of 145
A SOC is evaluating endpoint protection platforms. During testing, a brand-new malware variant with no prior hash record and no matching vendor signature is executed on a monitored host. The EPP flags the process as malicious because its runtime behavior—rapid file enumeration followed by mass encryption calls—statistically matches patterns learned from thousands of previous ransomware samples. Which detection capability of the endpoint technology is responsible for this catch?
Reviewed for accuracy · Report an issueNext question