exam questions

Exam 300-710 All Questions

View all questions & answers for the 300-710 exam

Exam 300-710 topic 1 question 161 discussion

Actual exam question from Cisco's 300-710
Question #: 161
Topic #: 1
[All 300-710 Questions]

A security engineer is configuring a remote Cisco FTD that has limited resources and internet bandwidth. Which malware action and protection option should be configured to reduce the requirement for cloud lookups?

  • A. Block File action and local malware analysis
  • B. Malware Cloud Lookup and dynamic analysis
  • C. Block Malware action and dynamic analysis
  • D. Block Malware action and local malware analysis
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
d0980cc
3 weeks ago
Selected Answer: D
I choose D. Consumes fewer resources. https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/file_policies_and_advanced_malware_protection.html#:~:text=Consumes%20fewer%20resources%20than%20dynamic%20analysis%2C%20and%20returns%20results%20more%20quickly%2C%20especially%20if%20the%20detected%20malware%20is%20common
upvoted 1 times
...
Silexis
3 months ago
Selected Answer: A
You can define a File Policy and block Files based on their type without doing any further check. Local File Analysis can be done for the other types of already not-blocked files as per below: "Local malware analysis allows a managed device to locally inspect executables, PDFs, office documents, and other types of files for the most common types of malware, using a detection rule set provided by the Cisco Talos Intelligence Group (Talos). Because local analysis does not query the AMP cloud, and does not run the file, local malware analysis saves time and system resources." https://www.cisco.com/c/en/us/td/docs/security/firepower/630/configuration/guide/fpmc-config-guide-v63/file_policies_and_advanced_malware_protection.html#concept_9CE3D1F1572541C695CE5C7682780311 In my opinion, combining the two from above, it will be the most resource savings actions
upvoted 1 times
Silexis
3 months ago
Correction - 2nd paragraph wanted to say LOCAL MALWARE ANALYSIS
upvoted 1 times
...
...
houhou12322
7 months, 3 weeks ago
B can be correct. I am not sure but if we choose malware Cloud Lookup the traffic will not be interrupted and for dynamic analysis the heavy lifting will bed done in the cloud, the FTD only needs to upload the file to the threatGrid. (its an idea i am not sure)
upvoted 1 times
...
m70855712
1 year, 5 months ago
Answer D is poorly worded. It should read: "ENABLE Block Malware action and ENABLE local malware analysis option" or another way to put it: "CONFIGURE Block Malware action and CONFIGURE local malware analysis option"
upvoted 3 times
...
THEODORABLE
1 year, 11 months ago
D--local malware analysis is less impacting and not A b/c Block files does not address Maleware.
upvoted 1 times
...
Cokamaniako
1 year, 12 months ago
Selected Answer: D
Local Malware Analysis Local malware analysis allows a managed device to locally inspect executables, PDFs, office documents, and other types of files for the most common types of malware, using a detection rule set provided by the Cisco Talos Intelligence Group (Talos). Because local analysis does not query the AMP cloud, and does not run the file, local malware analysis saves time and system resources. Block Malware rules allow you to calculate the SHA-256 hash value of specific file types, query the AMP cloud to determine if files traversing your network contain malware, then block files that represent threats. https://www.cisco.com/c/en/us/td/docs/security/firepower/623/configuration/guide/fpmc-config-guide-v623/file_policies_and_advanced_malware_protection.html#concept_9CE3D1F1572541C695CE5C7682780311
upvoted 2 times
...
Initial14
2 years, 1 month ago
Selected Answer: D
Only D in this case
upvoted 2 times
...
Joe_Blue
2 years, 1 month ago
Selected Answer: D
To reduce the requirement for cloud lookups and conserve limited resources and internet bandwidth on a remote Cisco FTD, the security engineer should configure the Block Malware action and local malware analysis option.
upvoted 1 times
...
freho
2 years, 2 months ago
Selected Answer: D
going with D too. rest makes no sense
upvoted 2 times
...
Mevijil
2 years, 2 months ago
Selected Answer: D
I'm pretty sure it is "D" - Block Malware and Local Analysis. The default behavior of Block Malware is to calculate the 256bit hash and do a AMP cloud lookup but local analysis is an option, according to the config guide: https://www.cisco.com/c/en/us/td/docs/security/firepower/623/configuration/guide/fpmc-config-guide-v623/file_policies_and_advanced_malware_protection.html#id_98267
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago