300-415 · Question #141
To configure file analysis for Advanced Malware Protection, which tasks are valid? (Choose three.)
The correct answer is A. Configure Threat Grid API key. B. Configure file types list. C. Enable file analysis.. To configure file analysis for Advanced Malware Protection (AMP), valid tasks include configuring the Threat Grid API key, defining a list of file types for analysis, and explicitly enabling the file analysis feature.
Question
Options
- AConfigure Threat Grid API key.
- BConfigure file types list.
- CEnable file analysis.
- DEnable HTTPS inbound to the WAN Edge router.
- EConfigure a security rule for Threat Grid.
How the community answered
(23 responses)- A87% (20)
- D4% (1)
- E9% (2)
Why each option
To configure file analysis for Advanced Malware Protection (AMP), valid tasks include configuring the Threat Grid API key, defining a list of file types for analysis, and explicitly enabling the file analysis feature.
Configuring the Threat Grid API key is essential for AMP file analysis, as it provides the necessary authentication and authorization for the network device to submit suspicious files to the Cisco Threat Grid cloud for deep analysis.
Configuring a file types list allows administrators to specify which types of files (e.g., executables, PDFs, archives) should be subjected to file analysis, helping to focus resources and prevent unnecessary analysis of benign files.
Enabling file analysis is a fundamental step to activate the feature on the device, ensuring that detected files are actually sent for inspection to the Threat Grid cloud according to the configured policies and turning on the functionality.
Enabling HTTPS inbound to the WAN Edge router is generally not a direct task for configuring file analysis itself; file submission to Threat Grid typically uses outbound connections from the WAN Edge.
While security rules define traffic inspection, 'Configure a security rule for Threat Grid' is less specific than enabling file analysis and configuring the API key and file types; the file analysis feature itself is integrated into security policies, but this choice is less fundamental than options A, B, and C.
Concept tested: Cisco AMP file analysis configuration
Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/security/ios-xe-17/security-book-xe/m-security.html#concept_r4z_4dh_h2b
Topics
Community Discussion
No community discussion yet for this question.