nerdexam
Cisco

300-710 · Question #14

Which action should you take when Cisco Threat Response notifies you that AMP has identified a file as malware?

The correct answer is A. Add the malicious file to the block list.. When Cisco Threat Response notifies you that AMP has identified a file as malware, the appropriate action is to add the malicious file to a block list.

Management and Troubleshooting

Question

Which action should you take when Cisco Threat Response notifies you that AMP has identified a file as malware?

Options

  • AAdd the malicious file to the block list.
  • BSend a snapshot to Cisco for technical support.
  • CForward the result of the investigation to an external threat-analysis engine.
  • DWait for Cisco Threat Response to automatically block the malware.

How the community answered

(35 responses)
  • A
    80% (28)
  • B
    3% (1)
  • C
    11% (4)
  • D
    6% (2)

Why each option

When Cisco Threat Response notifies you that AMP has identified a file as malware, the appropriate action is to add the malicious file to a block list.

AAdd the malicious file to the block list.Correct

Upon receiving a notification from Cisco Threat Response about malware identified by AMP, proactively adding the malicious file to a block list is essential. This action ensures that the file is prevented from executing, spreading, or being processed across the network and endpoints in the future, providing an explicit and enforced security measure beyond initial detection.

BSend a snapshot to Cisco for technical support.

Sending a snapshot to Cisco for technical support is usually performed for troubleshooting system issues, not as a primary response to a malware detection.

CForward the result of the investigation to an external threat-analysis engine.

Forwarding the investigation results to an external threat-analysis engine is unnecessary when Cisco AMP has already made a definitive malware identification.

DWait for Cisco Threat Response to automatically block the malware.

While AMP often automatically blocks known malware, waiting passively is not the proactive action *you* should take when notified; manual intervention to add to a block list ensures broader and custom enforcement.

Concept tested: Cisco AMP malware remediation actions

Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/management/configuration/guide/fpmc-config-guide-v65/configure_file_policies.html

Topics

#Cisco Threat Response#AMP#Malware Remediation#Block List Management

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice