300-710 · Question #392
A security engineer is reviewing a Cisco Secure Endpoint public cloud instance. The engineer discovers a malicious verdict for a SHA-256 hash of…
The correct answer is A. Add the hash to the custom detection list. To mitigate a known malicious file in Cisco Secure Endpoint, the security engineer can add the hash (SHA-256) to the custom detection list. This action ensures that Cisco Secure Endpoint will automatically block or quarantine any file matching this hash in the environment…
Question
A security engineer is reviewing a Cisco Secure Endpoint public cloud instance. The engineer discovers a malicious verdict for a SHA-256 hash of 689efc1ecdc23ec0b0885a80663e30ea013d493f8e88224b570a1234567890. Which configuration action must be done in Secure Endpoint console to mitigate the threat?
Options
- AAdd the hash to the custom detection list.
- BSet access control policy and deny files with the hash.
- CConfigure correlation policy to block the hash.
- DApply regular expression to block the malicious file.
How the community answered
(17 responses)- A71% (12)
- B6% (1)
- C18% (3)
- D6% (1)
Explanation
To mitigate a known malicious file in Cisco Secure Endpoint, the security engineer can add the hash (SHA-256) to the custom detection list. This action ensures that Cisco Secure Endpoint will automatically block or quarantine any file matching this hash in the environment, preventing it from executing or spreading further.
Topics
Community Discussion
No community discussion yet for this question.