nerdexam
Cisco

300-710 · Question #376

A security engineer sees an alert on Cisco Secure Endpoint console showing a malicious verdict for a file with the SHA-256 hash 0488537078abcdef048853abcdef048853abcdef048853abcdef048853abcdef048853.

The correct answer is C. Add the hash to custom detection list.. Custom Detection List > Simple 1. On the Add SHA-256 option, paste the SHA-256 code previously collected from the specific file you want to block 2. Once the Simple Custom Detection list is generated, navigate to Management > Policies and choose the policy where you want to apply

Configuration

Question

A security engineer sees an alert on Cisco Secure Endpoint console showing a malicious verdict for a file with the SHA-256 hash 0488537078abcdef048853abcdef048853abcdef048853abcdef048853abcdef048853. Which step will mitigate this threat?

Options

  • AAdd the hash to network block list.
  • BQuarantine the file on endpoint.
  • CAdd the hash to custom detection list.
  • DEnable firewall on infected endpoint.

How the community answered

(28 responses)
  • A
    18% (5)
  • B
    4% (1)
  • C
    71% (20)
  • D
    7% (2)

Explanation

Custom Detection List > Simple 1. On the Add SHA-256 option, paste the SHA-256 code previously collected from the specific file you want to block 2. Once the Simple Custom Detection list is generated, navigate to Management > Policies and choose the policy where you want to apply the list previously created custom-detection-list.html

Topics

#Cisco Secure Endpoint#Threat Mitigation#Custom File List#Security Policy

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice