ExamGecko
Question list
Search
Search

Question 223 - 350-701 discussion

Report
Export

A Cisco ESA network administrator has been tasked to use a newly installed service to help create policy based on the reputation verdict. During testing, it is discovered that the Cisco ESA is not dropping files that have an undetermined verdict. What is causing this issue?

A.

The policy was created to send a message to quarantine instead of drop

Answers
A.

The policy was created to send a message to quarantine instead of drop

B.

The file has a reputation score that is above the threshold

Answers
B.

The file has a reputation score that is above the threshold

C.

The file has a reputation score that is below the threshold

Answers
C.

The file has a reputation score that is below the threshold

D.

The policy was created to disable file analysis

Answers
D.

The policy was created to disable file analysis

Suggested answer: D

Explanation:

Maybe the "newly installed service" in this Qmentions about Advanced Malware Protection (AMP) which can be used along with ESA. AMP allows superior protection across the attack continuum.

+ File Reputation – captures a fingerprint of each file as it traverses the ESA and sends it to AMP's cloudbased intelligence network for a reputation verdict. Given these results, you can automatically block malicious files and apply administrator-defined policy.

+ File Analysis – provides the ability to analyze unknown files that are traversing the ESA. A highly secure sandbox environment enables AMP to glean precise details about the file's behavior and to combine that data with detailed human and machine analysis to determine the file's threat level.

This disposition is then fed into AMP cloud-based intelligence network and used to dynamically update and expand the AMP cloud data set for enhanced protection

asked 10/10/2024
Shan Panikker
28 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first