300-415 Question 226
Select 3An enterprise has implemented Cisco SD-WAN across its network. The security team wants to ensure that all file transfers within the environment are scanned for malware using Cisco AMP integration. Which of the following conditions must be met for AMP to function correctly in the Cisco SD-WAN environment?
- A
The vManage controller must have the AMP license activated and configured.
- B
The branch routers must have DIA (Direct Internet Access) enabled for AMP to scan traffic.
- C
Cisco Umbrella must be configured in conjunction with AMP for malware scanning to work.
- D
The file policy must be configured in vManage to redirect traffic to AMP for file scanning.
- E
The Cisco SD-WAN edge devices must have a security policy attached that includes AMP.
Show answer and explanation
Correct answers: A, D, E
Explanation
To integrate Cisco AMP with Cisco SD-WAN, the vManage controller must have an AMP license activated and properly configured. Additionally, a file policy must be configured in vManage to redirect traffic for malware scanning, and edge devices must have a security policy applied that includes AMP to enforce scanning. DIA is not mandatory, and Cisco Umbrella is not required for AMP to function, as AMP operates independently.
- A. Correct.
The vManage controller must have the AMP license activated and configured because AMP integration in Cisco SD-WAN requires licensing to enable malware scanning functionality.
- B. Incorrect.
Direct Internet Access (DIA) is not mandatory for AMP to function. AMP can scan traffic regardless of whether it is routed locally or via a central site.
- C. Incorrect.
Cisco Umbrella is a separate solution and is not mandatory for AMP functionality. While both Umbrella and AMP can work together, AMP can function independently to scan files.
- D. Correct.
The file policy must be configured in vManage to ensure that traffic is redirected to the AMP engine for malware scanning. Without this configuration, AMP cannot inspect files.
- E. Correct.
The SD-WAN edge devices must have a security policy applied that enables AMP. This ensures that file scanning is enforced at the edge.