300-710 · Question #325
An organization created a custom application that is being flagged by Cisco Secure Endpoint. The application must be exempt from being flagged. What is the process to meet the requirement?
The correct answer is C. Precalculate the hash value of the custom application and add it to the allowed applications. In Cisco Secure Endpoint (formerly AMP for Endpoints), the recommended way to prevent a known-good custom application from being flagged is to compute its SHA-256 hash and add that hash to the Allowed Applications list (also called the Application Allow List or Exclusion list…
Question
An organization created a custom application that is being flagged by Cisco Secure Endpoint. The application must be exempt from being flagged. What is the process to meet the requirement?
Options
- AConfigure the custom application to use the information-store paths.
- BAdd the custom application to the DFC list and update the policy.
- CPrecalculate the hash value of the custom application and add it to the allowed applications.
- DModify the custom detection list to exclude the custom application.
How the community answered
(35 responses)- A17% (6)
- B9% (3)
- C71% (25)
- D3% (1)
Explanation
In Cisco Secure Endpoint (formerly AMP for Endpoints), the recommended way to prevent a known-good custom application from being flagged is to compute its SHA-256 hash and add that hash to the Allowed Applications list (also called the Application Allow List or Exclusion list for specific hashes). Secure Endpoint uses file hashes as the fingerprint to identify files, so adding the hash allows the engine to recognize and skip that specific binary. The DFC list (B) relates to Device Flow Correlation. Option D refers to custom detection lists, which are used to flag files as malicious, not exempt them.
Topics
Community Discussion
No community discussion yet for this question.