350-701 · Question #574
A company recently discovered an attack propagating throughout their Windows network via a file named abc428565580xyz exe. The malicious file was uploaded to a Simple Custom Detection list in the…
The correct answer is A. Upload the malicious file to the Blocked Application Control List. The malicious file was uploaded to a Simple Custom Detection list in the AMP for Endpoints Portal, so the AMP already calculated the SHA-256 hash, you don't need to do it again. Since the file is a .exe file, which means it is executable, you should block it from the application
Question
A company recently discovered an attack propagating throughout their Windows network via a file named abc428565580xyz exe. The malicious file was uploaded to a Simple Custom Detection list in the AMP for Endpoints Portal and the currently applied policy for the Windows clients was updated to reference the detection list. Verification testing scans on known infected systems shows that AMP for Endpoints is not detecting the presence of this file as an indicator of compromise. What must be performed to ensure detection of the malicious file?
Options
- AUpload the malicious file to the Blocked Application Control List
- BUse an Advanced Custom Detection List instead of a Simple Custom Detection List
- CCheck the box in the policy configuration to send the file to Cisco Threat Grid for dynamic
- DUpload the SHA-256 hash for the file to the Simple Custom Detection List
How the community answered
(43 responses)- A70% (30)
- B7% (3)
- C5% (2)
- D19% (8)
Explanation
The malicious file was uploaded to a Simple Custom Detection list in the AMP for Endpoints Portal, so the AMP already calculated the SHA-256 hash, you don't need to do it again. Since the file is a .exe file, which means it is executable, you should block it from the application
Topics
Community Discussion
No community discussion yet for this question.