Cisco CCNP Security Core (SCOR) 350-701Content SecurityHard

A security engineer is troubleshooting an issue where legitimate software updates from a vendor's content delivery network (CDN) are being blocked by a Cisco Firepower Threat Defense (FTD) device. The FTD is configured with a strict file policy that blocks all executable files from untrusted sources. The vendor's CDN uses multiple, frequently changing IP addresses. Which FTD content security feature should the engineer adjust or configure to specifically allow these legitimate software updates while maintaining the strict file policy for other traffic?

  1. AApplication Detector settings to allow the specific update application.
  2. BURL Filtering policy to whitelist the vendor's domain.
  3. CAdvanced Malware Protection (AMP) for Firepower exclusions.
  4. DIntrusion policy to disable relevant exploit signatures.
Show answer & explanation

Correct answer: C. Advanced Malware Protection (AMP) for Firepower exclusions.

When dealing with legitimate files from trusted sources that are being blocked by a strict file policy or malware detection, the appropriate action is to create an exclusion within the Advanced Malware Protection (AMP) for Firepower settings. This allows specific files (identified by hash) or files from trusted sources/domains to bypass the malware analysis, ensuring legitimate updates are not blocked while maintaining overall strictness.

Why the other options are wrong

  • A. Application Detector settings control application usage, not the allowance of specific files or overriding malware detection for downloads.
  • B. URL filtering whitelists domains for web access but doesn't override file policy or AMP decisions for specific file types or malware status.
  • D. Disabling IPS signatures is for exploit prevention, not for allowing legitimate files that are being blocked by file/malware policies.

AMP for Firepower Exclusions

A configuration within Cisco Firepower's Advanced Malware Protection (AMP) that allows administrators to specify trusted files (by hash) or sources (by domain/IP) to bypass malware analysis, preventing legitimate content from being incorrectly blocked.

  • Used to whitelist known good files or sources.
  • Prevents false positives from strict malware detection.
  • Can be based on file hash, file type, application, or network zone.

Memory trick: AMP Exclusion: Allowing Approved Artifacts, Avoiding Accidental Blocks.

More Content Security questions