350-701 · Question #763
An engineer is configuring Cisco Secure Endpoint to enhance security by preventing the execution of certain files by users. The engineer needs to ensure that the specific executable file name…
The correct answer is B. Configure application control blocked applications list. To prevent a specific executable file from running on endpoints without quarantining it, the engineer must configure the Application Control blocked applications list in Cisco Secure Endpoint.
Question
An engineer is configuring Cisco Secure Endpoint to enhance security by preventing the execution of certain files by users. The engineer needs to ensure that the specific executable file name Cisco_Software_0505446151.exe is blocked from running while never being quarantined. What must the engineer configure to meet the requirement?
Options
- ACreate advanced custom detection list.
- BConfigure application control blocked applications list.
- CImplement simple custom detection list.
- DEnable scheduled scans to detect and block the executable files.
How the community answered
(64 responses)- A3% (2)
- B73% (47)
- C8% (5)
- D16% (10)
Why each option
To prevent a specific executable file from running on endpoints without quarantining it, the engineer must configure the Application Control blocked applications list in Cisco Secure Endpoint.
An advanced custom detection list is typically used for defining custom indicators of compromise (IOCs) for detection and blocking/quarantining, which might involve quarantine and is more complex than simply blocking an application.
Cisco Secure Endpoint's Application Control feature allows administrators to specify applications or executables by name (or other attributes) to be blocked from running on endpoints, fulfilling the requirement to block execution without quarantining.
A simple custom detection list is also for custom IOCs and may lead to quarantine, not just preventing execution.
Scheduled scans are for detecting and remediating threats, often involving quarantine or deletion, and do not specifically provide the granular control to *only* block execution of a known good (but unwanted) application without quarantining.
Concept tested: Cisco Secure Endpoint Application Control
Source: https://docs.amp.cisco.com/SecureEndpointConsoleUserGuide-latest.pdf#page=160
Topics
Community Discussion
No community discussion yet for this question.