300-710 · Question #113
A user within an organization opened a malicious file on a workstation which in turn caused a ransomware attack on the network. What should be configured within the Cisco FMC to ensure the file is tes
The correct answer is D. Dynamic analysis. Dynamic Analysis in Cisco FMC submits suspicious files to a cloud-based sandbox environment (Cisco Threat Grid) where they are executed and observed for malicious behavior in a safe, isolated environment. This behavioral testing approach detects threats like ransomware that may e
Question
A user within an organization opened a malicious file on a workstation which in turn caused a ransomware attack on the network. What should be configured within the Cisco FMC to ensure the file is tested for viruses on a sandbox system?
Options
- ACapacity handling
- BLocal malware analysis
- CSpere analysis
- DDynamic analysis
How the community answered
(28 responses)- A14% (4)
- B4% (1)
- C7% (2)
- D75% (21)
Explanation
Dynamic Analysis in Cisco FMC submits suspicious files to a cloud-based sandbox environment (Cisco Threat Grid) where they are executed and observed for malicious behavior in a safe, isolated environment. This behavioral testing approach detects threats like ransomware that may evade signature-based detection. 'Local malware analysis' (B) uses local engines with pre-downloaded signatures but does not involve a sandbox. 'Capacity handling' (A) manages resource constraints, and 'Spere analysis' (C) is not a valid Cisco feature.
Topics
Community Discussion
No community discussion yet for this question.