nerdexam
Cisco

300-740 · Question #53

Refer to the exhibit. A security engineer must configure a posture policy in Cisco ISE to ensure that employee laptops have a critical patch for WannaCry installed before they can access the…

The correct answer is B. File Condition. Option B is correct because a File Condition in Cisco ISE posture checks for the existence, version, or date of a specific file on the endpoint - when Microsoft's WannaCry patch (MS17-010) is applied, it installs or modifies specific system files, and ISE can verify the patch…

User and Device Security

Question

Refer to the exhibit. A security engineer must configure a posture policy in Cisco ISE to ensure that employee laptops have a critical patch for WannaCry installed before they can access the network. Which posture condition must the engineer configure?

Options

  • APatch Management Condition
  • BFile Condition
  • CAnti-Virus Condition
  • DAnti-Malware Condition

How the community answered

(54 responses)
  • A
    2% (1)
  • B
    81% (44)
  • C
    9% (5)
  • D
    7% (4)

Explanation

Option B is correct because a File Condition in Cisco ISE posture checks for the existence, version, or date of a specific file on the endpoint - when Microsoft's WannaCry patch (MS17-010) is applied, it installs or modifies specific system files, and ISE can verify the patch is present by confirming those files exist with the correct attributes.

Why the distractors are wrong:

  • A (Patch Management Condition): This checks whether a patch management application (e.g., WSUS agent, SCCM client) is installed and running - it does not verify that any specific patch has been applied.
  • C (Anti-Virus Condition): This checks whether an AV product is installed, enabled, and has up-to-date definitions - unrelated to OS patches.
  • D (Anti-Malware Condition): Similar to AV, this checks for the presence and health of an anti-malware product - not OS-level patch status.

Memory tip: Think of it this way - patches leave files behind. If you need to confirm a specific patch (not patch software, not AV software) exists on a machine, you verify the files it dropped. When the ISE options don't include a dedicated "hotfix/Windows Update" condition, File Condition is your granular fallback for confirming a specific patch by its installed artifacts.

Topics

#Cisco ISE#Posture Compliance#File Condition#Patch Verification

Community Discussion

No community discussion yet for this question.

Full 300-740 Practice