700-270 · Question #19
Where are files that are awaiting a disposition check held during file analysis?
The correct answer is B. cloud-based sandbox. Option B is correct because Cisco's file analysis process (used in products like Cisco Secure Firewall/Firepower with AMP integration) submits suspicious files to a cloud-based sandbox - an isolated, instrumented environment where the file is executed and observed to determine it
Question
Where are files that are awaiting a disposition check held during file analysis?
Options
- Acloud-based, company-specific repository
- Bcloud-based sandbox
- CCisco ASA SSD drive
- Disolated VLAN
How the community answered
(23 responses)- A9% (2)
- B87% (20)
- D4% (1)
Explanation
Option B is correct because Cisco's file analysis process (used in products like Cisco Secure Firewall/Firepower with AMP integration) submits suspicious files to a cloud-based sandbox - an isolated, instrumented environment where the file is executed and observed to determine its disposition (clean, malicious, or unknown) without risking the production network.
- A (company-specific repository) is wrong because files pending disposition aren't stored in a customer-owned repository; they're sent to Cisco's threat intelligence cloud infrastructure for analysis.
- C (Cisco ASA SSD drive) is wrong because the ASA has no dedicated local storage role in the disposition workflow - analysis happens externally, not on the appliance's drive.
- D (isolated VLAN) is wrong because a VLAN is a network segmentation concept, not a file holding mechanism; VLANs don't store or analyze files.
Memory tip: Think of a sandbox as a "safe playground" - files that haven't been cleared yet need to play in the cloud sandbox first before they're allowed into your environment. Cloud = central, scalable analysis; sandbox = isolated execution.
Topics
Community Discussion
No community discussion yet for this question.