nerdexam
Cisco

300-710 · Question #423

An engineer is deploying Cisco Secure Endpoint for the first time and on endpoint with MAC address 50:54:15:04:0:AB. The engineer must make sure that during the testing phase no files are isolated…

The correct answer is D. Audit. Cisco Secure Endpoint offers several policy modes. The 'Audit' policy mode is a passive, non-blocking mode designed for initial deployment and testing phases. It monitors and logs endpoint activity-file events, network connections, process activity-without taking any…

Deployment

Question

An engineer is deploying Cisco Secure Endpoint for the first time and on endpoint with MAC address 50:54:15:04:0:AB. The engineer must make sure that during the testing phase no files are isolated and network connections must not be blocked. Which policy type must be configured to accomplish the task?

Options

  • ATriage
  • BQuarantine
  • CProtect
  • DAudit

How the community answered

(45 responses)
  • A
    11% (5)
  • B
    7% (3)
  • C
    2% (1)
  • D
    80% (36)

Explanation

Cisco Secure Endpoint offers several policy modes. The 'Audit' policy mode is a passive, non-blocking mode designed for initial deployment and testing phases. It monitors and logs endpoint activity-file events, network connections, process activity-without taking any enforcement action such as file quarantine or network blocking. This allows engineers to observe what detections would occur in the environment before enforcing any blocking. 'Protect' (Option C) enables active blocking and quarantine. 'Triage' and 'Quarantine' are also enforcement-oriented modes, making Audit the correct choice for a no-impact testing phase.

Topics

#Secure Endpoint Policies#Audit Mode#Endpoint Deployment#Policy Configuration

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice