A user within an organization opened a malicious file on a workstation which in turn caused a ransomware attack on the network. What should be configured within the Cisco FMC to ensure the file is tested for viruses on a sandbox system?
D. Dynamic analysis.
To ensure that files are tested for viruses on a sandbox system, the Cisco FMC should be configured to perform dynamic analysis on files. Dynamic analysis is a security technique that involves executing files in a sandbox environment and observing their behavior to determine whether they are malicious.
The Cisco FMC supports dynamic analysis using its Advanced Malware Protection (AMP) feature, which includes a cloud-based sandbox for analyzing files. The AMP feature analyzes files in real-time to detect malware and other malicious activity.
Local malware analysis and spere analysis are not appropriate solutions for testing files for viruses on a sandbox system. Local malware analysis involves scanning files using antivirus software installed on the local system, which is not as effective as dynamic analysis. Sphere analysis involves analyzing files in a separate virtual environment, but it is not as comprehensive as dynamic analysis.
Capacity handling is a general term that refers to the ability of a system to handle a large volume of traffic or data, and is not related to testing files for viruses on a sandbox system.
The answer is correct, and this link will explain each option in case you are interested to know the differences:
https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Reference_a_wrapper_Chapter_topic_here.html#ID-2199-000005fa
upvoted 3 times
...
This section is not available anymore. Please use the main Exam Page.300-710 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
tanri04
10 months, 3 weeks agoeazy99
1 year, 10 months ago