nerdexam
Cisco

350-701 · Question #763

An engineer is configuring Cisco Secure Endpoint to enhance security by preventing the execution of certain files by users. The engineer needs to ensure that the specific executable file name…

The correct answer is B. Configure application control blocked applications list. To prevent a specific executable file from running on endpoints without quarantining it, the engineer must configure the Application Control blocked applications list in Cisco Secure Endpoint.

Submitted by chen.hong· Mar 30, 2026Endpoint Protection and Detection

Question

An engineer is configuring Cisco Secure Endpoint to enhance security by preventing the execution of certain files by users. The engineer needs to ensure that the specific executable file name Cisco_Software_0505446151.exe is blocked from running while never being quarantined. What must the engineer configure to meet the requirement?

Options

  • ACreate advanced custom detection list.
  • BConfigure application control blocked applications list.
  • CImplement simple custom detection list.
  • DEnable scheduled scans to detect and block the executable files.

How the community answered

(64 responses)
  • A
    3% (2)
  • B
    73% (47)
  • C
    8% (5)
  • D
    16% (10)

Why each option

To prevent a specific executable file from running on endpoints without quarantining it, the engineer must configure the Application Control blocked applications list in Cisco Secure Endpoint.

ACreate advanced custom detection list.

An advanced custom detection list is typically used for defining custom indicators of compromise (IOCs) for detection and blocking/quarantining, which might involve quarantine and is more complex than simply blocking an application.

BConfigure application control blocked applications list.Correct

Cisco Secure Endpoint's Application Control feature allows administrators to specify applications or executables by name (or other attributes) to be blocked from running on endpoints, fulfilling the requirement to block execution without quarantining.

CImplement simple custom detection list.

A simple custom detection list is also for custom IOCs and may lead to quarantine, not just preventing execution.

DEnable scheduled scans to detect and block the executable files.

Scheduled scans are for detecting and remediating threats, often involving quarantine or deletion, and do not specifically provide the granular control to *only* block execution of a known good (but unwanted) application without quarantining.

Concept tested: Cisco Secure Endpoint Application Control

Source: https://docs.amp.cisco.com/SecureEndpointConsoleUserGuide-latest.pdf#page=160

Topics

#Cisco Secure Endpoint#Application control#Executable blocking

Community Discussion

No community discussion yet for this question.

Full 350-701 Practice