nerdexam
Cisco

300-710 · Question #10

An engineer is troubleshooting a file that is being blocked by a Cisco FTD device on the network. The user is reporting that the file is not malicious. Which action does the engineer take to…

The correct answer is A. Identify the file in the intrusion events and submit it to Threat Grid for analysis. To validate a file blocked by a Cisco FTD device that a user claims is not malicious, the engineer should identify the file in intrusion events and submit it to Threat Grid for detailed analysis.

Management and Troubleshooting

Question

An engineer is troubleshooting a file that is being blocked by a Cisco FTD device on the network. The user is reporting that the file is not malicious. Which action does the engineer take to identify the file and validate whether or not it is malicious?

Options

  • AIdentify the file in the intrusion events and submit it to Threat Grid for analysis.
  • BUse FMC file analysis to look for the file and select Analyze to determine its disposition.
  • CUse the context explorer to find the file and download it to the local machine for investigation.
  • DRight click the connection event and send the file to AMP for Endpoints to see if the hash is

How the community answered

(21 responses)
  • A
    76% (16)
  • B
    5% (1)
  • C
    14% (3)
  • D
    5% (1)

Why each option

To validate a file blocked by a Cisco FTD device that a user claims is not malicious, the engineer should identify the file in intrusion events and submit it to Threat Grid for detailed analysis.

AIdentify the file in the intrusion events and submit it to Threat Grid for analysis.Correct

When a file is blocked and its maliciousness is disputed, identifying it in the intrusion events within the Cisco Firepower Management Center (FMC) helps understand the reason for the block. Submitting the file to Cisco Threat Grid, Cisco's advanced malware analysis sandbox, provides a detailed behavioral analysis and disposition, confirming or refuting its malicious nature through deep inspection.

BUse FMC file analysis to look for the file and select Analyze to determine its disposition.

While FMC has file analysis, submitting to Threat Grid offers a more comprehensive sandbox analysis for disposition validation, which is typically the most thorough method for disputed files.

CUse the context explorer to find the file and download it to the local machine for investigation.

Downloading a potentially malicious file to a local machine for investigation is a security risk and not a recommended practice for validating its disposition.

DRight click the connection event and send the file to AMP for Endpoints to see if the hash is

Right-clicking a connection event and sending the file to AMP for Endpoints is not the direct method for analyzing its disposition from the FTD/FMC perspective; AMP for Endpoints focuses on endpoint protection.

Concept tested: Cisco FTD Threat Grid file analysis

Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/firepower_management_center_and_threat_grid_integration.html

Topics

#File Blocking#Threat Analysis#Firepower FTD#Troubleshooting

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice