300-710 · Question #129
An engineer has been tasked with using Cisco FMC to determine if files being sent through the network are malware. Which two configuration tasks must be performed to achieve this file lookup? (Choose
The correct answer is D. The Cisco FMC needs to connect with the FireAMP Cloud. E. The Cisco FMC needs to include a file inspection policy for malware lookup.. Two things are required: (D) FMC must be connected to the FireAMP Cloud (Cisco AMP Cloud) so it can submit SHA-256 file hashes and receive back malware dispositions in real time; and (E) a file inspection policy (file policy) must be configured and attached to an access control p
Question
An engineer has been tasked with using Cisco FMC to determine if files being sent through the network are malware. Which two configuration tasks must be performed to achieve this file lookup? (Choose two.)
Options
- AThe Cisco FMC needs to include a SSL decryption policy.
- BThe Cisco FMC needs to connect to the Cisco AMP for Endpoints service.
- CThe Cisco FMC needs to connect to the Cisco ThreatGrid service directly for sandboxing.
- DThe Cisco FMC needs to connect with the FireAMP Cloud.
- EThe Cisco FMC needs to include a file inspection policy for malware lookup.
How the community answered
(60 responses)- A17% (10)
- B7% (4)
- C3% (2)
- D73% (44)
Explanation
Two things are required: (D) FMC must be connected to the FireAMP Cloud (Cisco AMP Cloud) so it can submit SHA-256 file hashes and receive back malware dispositions in real time; and (E) a file inspection policy (file policy) must be configured and attached to an access control policy to define which file types to inspect and what action to take (detect, block, etc.). SSL decryption (A) is relevant only for encrypted traffic and is not a prerequisite for basic file lookup. Connecting to AMP for Endpoints (B) is for endpoint telemetry, not network file lookup. Direct ThreatGrid integration (C) is for sandboxing unknown files, which is a separate, optional step beyond basic malware lookup.
Topics
Community Discussion
No community discussion yet for this question.