nerdexam
Cisco

300-745 · Question #17

Refer to the exhibit. A retail company recently deployed a file inspection feature using secure endpoint. The file inspection must detect and prevent the execution of malicious files on machines…

The correct answer is D. Policy rule is in audit mode. The exhibit shows that the malicious file was detected but not quarantined with the note "In audit only mode." This indicates that the secure endpoint policy was set to audit mode, which only logs detections instead of blocking execution. To prevent malicious files from…

Advanced Threat and Endpoint Security

Question

Refer to the exhibit. A retail company recently deployed a file inspection feature using secure endpoint. The file inspection must detect and prevent the execution of malicious files on machines. During testing, logs showed that certain malicious files are still being executed despite the presence of the security measure. To understand why the threats are not being blocked, it is essential to investigate the configuration of secure endpoint policies. Which configuration is allowing the files to execute?

Exhibit

300-745 question #17 exhibit

Options

  • AFiles are not malicious.
  • BPolicy must block the network connections.
  • CPolicy rule is disabled.
  • DPolicy rule is in audit mode.

How the community answered

(34 responses)
  • A
    6% (2)
  • B
    3% (1)
  • C
    9% (3)
  • D
    82% (28)

Explanation

The exhibit shows that the malicious file was detected but not quarantined with the note "In audit only mode." This indicates that the secure endpoint policy was set to audit mode, which only logs detections instead of blocking execution. To prevent malicious files from running, the policy must be switched from audit mode to enforcement (block) mode.

Topics

#Secure Endpoint#audit mode#file inspection#policy configuration

Community Discussion

No community discussion yet for this question.

Full 300-745 Practice