350-701 · Question #746
Which action blocks specific IP addresses whenever a computer with Cisco Secure Endpoint installed connects to the network?
The correct answer is B. Create an IP Block & Allow list and add the IP addresses. IP Block & Allow Lists in Cisco Secure Endpoint are specifically designed to control network traffic at the IP address level - when an endpoint connects to the network, the agent enforces these lists by blocking or allowing connections to the defined IPs across all…
Question
Which action blocks specific IP addresses whenever a computer with Cisco Secure Endpoint installed connects to the network?
Options
- ACreate an application block list and add the IP addresses.
- BCreate an IP Block & Allow list and add the IP addresses.
- CCreate an advanced custom detection policy and add the IP addresses.
- DCreate a simple custom detection policy and add the IP addresses.
How the community answered
(55 responses)- A4% (2)
- B87% (48)
- C7% (4)
- D2% (1)
Explanation
IP Block & Allow Lists in Cisco Secure Endpoint are specifically designed to control network traffic at the IP address level - when an endpoint connects to the network, the agent enforces these lists by blocking or allowing connections to the defined IPs across all applications.
Why the distractors are wrong:
- A (Application Block List): This targets executable files/applications by name or hash, not network IP addresses.
- C (Advanced Custom Detection): This is used to detect malicious files using custom signatures (e.g., MD5 hashes or TETRA signatures), not IP-based network blocking.
- D (Simple Custom Detection): Also file-focused - it blocks specific files by SHA-256 hash, not by IP address.
Memory tip: Match the word "IP" in the question to the only option that literally contains "IP" in its name - IP Block & Allow List. If the threat is network-based (IP addresses), the control must be network-based too.
Topics
Community Discussion
No community discussion yet for this question.