300-710 · Question #10
An engineer is troubleshooting a file that is being blocked by a Cisco FTD device on the network. The user is reporting that the file is not malicious. Which action does the engineer take to…
The correct answer is A. Identify the file in the intrusion events and submit it to Threat Grid for analysis. To validate a file blocked by a Cisco FTD device that a user claims is not malicious, the engineer should identify the file in intrusion events and submit it to Threat Grid for detailed analysis.
Question
An engineer is troubleshooting a file that is being blocked by a Cisco FTD device on the network. The user is reporting that the file is not malicious. Which action does the engineer take to identify the file and validate whether or not it is malicious?
Options
- AIdentify the file in the intrusion events and submit it to Threat Grid for analysis.
- BUse FMC file analysis to look for the file and select Analyze to determine its disposition.
- CUse the context explorer to find the file and download it to the local machine for investigation.
- DRight click the connection event and send the file to AMP for Endpoints to see if the hash is
How the community answered
(21 responses)- A76% (16)
- B5% (1)
- C14% (3)
- D5% (1)
Why each option
To validate a file blocked by a Cisco FTD device that a user claims is not malicious, the engineer should identify the file in intrusion events and submit it to Threat Grid for detailed analysis.
When a file is blocked and its maliciousness is disputed, identifying it in the intrusion events within the Cisco Firepower Management Center (FMC) helps understand the reason for the block. Submitting the file to Cisco Threat Grid, Cisco's advanced malware analysis sandbox, provides a detailed behavioral analysis and disposition, confirming or refuting its malicious nature through deep inspection.
While FMC has file analysis, submitting to Threat Grid offers a more comprehensive sandbox analysis for disposition validation, which is typically the most thorough method for disputed files.
Downloading a potentially malicious file to a local machine for investigation is a security risk and not a recommended practice for validating its disposition.
Right-clicking a connection event and sending the file to AMP for Endpoints is not the direct method for analyzing its disposition from the FTD/FMC perspective; AMP for Endpoints focuses on endpoint protection.
Concept tested: Cisco FTD Threat Grid file analysis
Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/firepower_management_center_and_threat_grid_integration.html
Topics
Community Discussion
No community discussion yet for this question.