Question: How does the Cisco Secure Firewall Threat Defense system check the AMP cloud for a file disposition? It sends an SHA - 2 5 6
How does the Cisco Secure Firewall Threat Defense system check the AMP cloud for a file disposition?
It sends an SHA hash of the file to the cloud that uniquely identifies the file, and the cloud returns a disposition for the hash value associated with the file.
It sends the entire file to the cloud, where the cloud runs the file in a sandbox environment to determine the file disposition, which is returned to the system.
It sends the filename to the cloud, which checks the filename against a list of known malware to determine the file disposition, which is returned to the system.
It sends the filename and SHA has value to the cloud, and the cloud returns a disposition for both the filename and hash value.
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
