300-710 · Question #423
An engineer is deploying Cisco Secure Endpoint for the first time and on endpoint with MAC address 50:54:15:04:0:AB. The engineer must make sure that during the testing phase no files are isolated…
The correct answer is D. Audit. Cisco Secure Endpoint offers several policy modes. The 'Audit' policy mode is a passive, non-blocking mode designed for initial deployment and testing phases. It monitors and logs endpoint activity-file events, network connections, process activity-without taking any…
Question
An engineer is deploying Cisco Secure Endpoint for the first time and on endpoint with MAC address 50:54:15:04:0:AB. The engineer must make sure that during the testing phase no files are isolated and network connections must not be blocked. Which policy type must be configured to accomplish the task?
Options
- ATriage
- BQuarantine
- CProtect
- DAudit
How the community answered
(45 responses)- A11% (5)
- B7% (3)
- C2% (1)
- D80% (36)
Explanation
Cisco Secure Endpoint offers several policy modes. The 'Audit' policy mode is a passive, non-blocking mode designed for initial deployment and testing phases. It monitors and logs endpoint activity-file events, network connections, process activity-without taking any enforcement action such as file quarantine or network blocking. This allows engineers to observe what detections would occur in the environment before enforcing any blocking. 'Protect' (Option C) enables active blocking and quarantine. 'Triage' and 'Quarantine' are also enforcement-oriented modes, making Audit the correct choice for a no-impact testing phase.
Topics
Community Discussion
No community discussion yet for this question.