300-710 · Question #376
A security engineer sees an alert on Cisco Secure Endpoint console showing a malicious verdict for a file with the SHA-256 hash 0488537078abcdef048853abcdef048853abcdef048853abcdef048853abcdef048853.
The correct answer is C. Add the hash to custom detection list.. Custom Detection List > Simple 1. On the Add SHA-256 option, paste the SHA-256 code previously collected from the specific file you want to block 2. Once the Simple Custom Detection list is generated, navigate to Management > Policies and choose the policy where you want to apply
Question
A security engineer sees an alert on Cisco Secure Endpoint console showing a malicious verdict for a file with the SHA-256 hash 0488537078abcdef048853abcdef048853abcdef048853abcdef048853abcdef048853. Which step will mitigate this threat?
Options
- AAdd the hash to network block list.
- BQuarantine the file on endpoint.
- CAdd the hash to custom detection list.
- DEnable firewall on infected endpoint.
How the community answered
(28 responses)- A18% (5)
- B4% (1)
- C71% (20)
- D7% (2)
Explanation
Custom Detection List > Simple 1. On the Add SHA-256 option, paste the SHA-256 code previously collected from the specific file you want to block 2. Once the Simple Custom Detection list is generated, navigate to Management > Policies and choose the policy where you want to apply the list previously created custom-detection-list.html
Topics
Community Discussion
No community discussion yet for this question.