nerdexam
Cisco

300-720 · Question #78

Refer to the exhibit. How should this configuration be modified to stop delivering Zero Day malware attacks?

The correct answer is B. Change File Analysis Pending action from Deliver As Is to Quarantine. Zero-day malware refers to threats that are new or unknown and not yet identified by traditional signature-based detection. The Cisco ESA's Advanced Malware Protection (AMP) feature can submit suspicious files to Cisco Threat Grid for dynamic sandboxing analysis. While a file…

Cisco ESA Spam Control and Anti-Malware

Question

Refer to the exhibit. How should this configuration be modified to stop delivering Zero Day malware attacks?

Exhibit

300-720 question #78 exhibit

Options

  • AChange Unscannable Action from Deliver As Is to Quarantine.
  • BChange File Analysis Pending action from Deliver As Is to Quarantine.
  • CConfigure mailbox auto-remediation.
  • DApply Prepend on Modify Message Subject under Malware Attachments.

How the community answered

(42 responses)
  • A
    2% (1)
  • B
    76% (32)
  • C
    14% (6)
  • D
    7% (3)

Explanation

Zero-day malware refers to threats that are new or unknown and not yet identified by traditional signature-based detection. The Cisco ESA's Advanced Malware Protection (AMP) feature can submit suspicious files to Cisco Threat Grid for dynamic sandboxing analysis. While a file is awaiting sandbox analysis results, its verdict is pending. If the 'File Analysis Pending' action is set to 'Deliver As Is,' the ESA will deliver the email before the analysis completes, potentially allowing zero-day malware through. Changing this action to 'Quarantine' holds the message until the analysis verdict is returned, preventing delivery of potentially malicious content. Option A (Unscannable Action) handles files that cannot be scanned at all, which is a different scenario. Options C and D address remediation and notification, not pre-delivery blocking.

Topics

#Zero Day Malware#Advanced Malware Protection (AMP)#Cisco ESA Configuration#File Analysis Action

Community Discussion

No community discussion yet for this question.

Full 300-720 Practice