300-720 · Question #161
Which action do Outbreak Filters take to stop small-scale and nonviral attacks, such as phishing scams and malware distribution sites?
The correct answer is A. Rewrite URLs to redirect traffic to potentially harmful websites through a web security proxy. Cisco Outbreak Filters combat small-scale, nonviral threats like phishing and malware distribution by rewriting URLs found within suspicious emails. When a user clicks a rewritten URL, their traffic is redirected through a Cisco web security proxy (such as Cisco Umbrella or the…
Question
Which action do Outbreak Filters take to stop small-scale and nonviral attacks, such as phishing scams and malware distribution sites?
Options
- ARewrite URLs to redirect traffic to potentially harmful websites through a web security proxy
- BBlock all emails from email domains associated with potentially harmful websites.
- CStrip all attachments from email domains associated with potentially harmful websites.
- DQuarantine messages that contain links to potentially harmful websites until the site is taken
How the community answered
(67 responses)- A88% (59)
- B3% (2)
- C7% (5)
- D1% (1)
Explanation
Cisco Outbreak Filters combat small-scale, nonviral threats like phishing and malware distribution by rewriting URLs found within suspicious emails. When a user clicks a rewritten URL, their traffic is redirected through a Cisco web security proxy (such as Cisco Umbrella or the Web Security Appliance), which evaluates the destination site in real time. This is particularly effective against phishing because the threat can be blocked at click-time even if the site was not flagged at email-delivery time. Blocking all emails from associated domains (B) would cause too many false positives. Stripping attachments (C) does not address URL-based threats. Quarantining until a site is taken down (D) describes a related but different action Outbreak Filters can take; URL rewriting is the specific mechanism for nonviral, link-based attacks.
Topics
Community Discussion
No community discussion yet for this question.