SOPHOS ENGINEER ET80 UPDATED FINAL EXAM
QUESTIONS AND ANSWERS SURE A+
✔✔What happens when Sophos Zero-Day Protection reviews a hash file it hasn't seen
before? - ✔✔The a copy of the suspicious file is sent to Sophos where it is opened in a
sandbox environment and monitored. Once analysed, the threat intelligence is sent to
the firewall where it is either blocked or allowed depending. A report is then created for
the threat incident.
✔✔How does Sophos Deep Learning work? - ✔✔Millions of samples of both good and
bad files are fed to the model, and each feature of the file is defined then labelled, such
as Size, Vendor and Printable settings. This model is then used to review the suspicious
file to recognise and predict if it is malicious or legitimate
✔✔What is Application control? - ✔✔This is a service used to reduce the attack surface
by restricting what applications are allowed
✔✔What is Synchronized App control? - ✔✔Sophos Firewall sees app traffic that does
not match a signature, but Sophos Endpoint shares the app name, path and category to
the Sophos firewall for classification, so the firewall can categorise and control traffic
✔✔What happens in the Exploitation Phase of the Attack Kill Chain? - ✔✔The use of a
vulnerability to execute code on the victims machine
✔✔What types of attacks are used to exploit Web Servers? - ✔✔XSS, SQL Injection,
Protocol Violations and Cross Site Scripting
✔✔How does Sophos Web Server Protection work? - ✔✔It use pre-configured
templates to protect Web Servers. It works as a reverse proxy in the DMZ for inbound
traffic. It uses a Web Application firewall to filter traffic, sign cookies and scan for
malware. It can also authenticate users before they access the web server
✔✔What is an IPS? - ✔✔Intrusion Prevention System
✔✔What does an IPS do? - ✔✔Monitor network for malicious activity and takes action
to block intrusions
✔✔What happens in the Command and Control Phase of the Attack Kill Chain? -
✔✔The installed malware makes a connection to a remote command and control centre
for remote manipulation of the Infected machine
✔✔What does Advanced Threat Protection do? - ✔✔It monitors all outgoing traffic and
detects and blocks malicious outgoing traffic. This stops infected machines from
contacting command and control centres. If this happens, and alert is recorded within
QUESTIONS AND ANSWERS SURE A+
✔✔What happens when Sophos Zero-Day Protection reviews a hash file it hasn't seen
before? - ✔✔The a copy of the suspicious file is sent to Sophos where it is opened in a
sandbox environment and monitored. Once analysed, the threat intelligence is sent to
the firewall where it is either blocked or allowed depending. A report is then created for
the threat incident.
✔✔How does Sophos Deep Learning work? - ✔✔Millions of samples of both good and
bad files are fed to the model, and each feature of the file is defined then labelled, such
as Size, Vendor and Printable settings. This model is then used to review the suspicious
file to recognise and predict if it is malicious or legitimate
✔✔What is Application control? - ✔✔This is a service used to reduce the attack surface
by restricting what applications are allowed
✔✔What is Synchronized App control? - ✔✔Sophos Firewall sees app traffic that does
not match a signature, but Sophos Endpoint shares the app name, path and category to
the Sophos firewall for classification, so the firewall can categorise and control traffic
✔✔What happens in the Exploitation Phase of the Attack Kill Chain? - ✔✔The use of a
vulnerability to execute code on the victims machine
✔✔What types of attacks are used to exploit Web Servers? - ✔✔XSS, SQL Injection,
Protocol Violations and Cross Site Scripting
✔✔How does Sophos Web Server Protection work? - ✔✔It use pre-configured
templates to protect Web Servers. It works as a reverse proxy in the DMZ for inbound
traffic. It uses a Web Application firewall to filter traffic, sign cookies and scan for
malware. It can also authenticate users before they access the web server
✔✔What is an IPS? - ✔✔Intrusion Prevention System
✔✔What does an IPS do? - ✔✔Monitor network for malicious activity and takes action
to block intrusions
✔✔What happens in the Command and Control Phase of the Attack Kill Chain? -
✔✔The installed malware makes a connection to a remote command and control centre
for remote manipulation of the Infected machine
✔✔What does Advanced Threat Protection do? - ✔✔It monitors all outgoing traffic and
detects and blocks malicious outgoing traffic. This stops infected machines from
contacting command and control centres. If this happens, and alert is recorded within