350-201 exam dumps

350-201 practice question 158 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 158

Select 4

You are managing a Cisco Secure Endpoint (formerly AMP for Endpoints) deployment in your organization. Recently, users have reported that a specific benign application is being flagged by a custom detection rule you created. How should you troubleshoot and resolve this issue while maintaining the security posture?

  1. A

    Verify the conditions and logic defined in the custom detection rule to ensure they appropriately target the intended threat.

  2. B

    Review the Secure Endpoint event logs to confirm that the application matches the criteria of the detection rule.

  3. C

    Disable the custom detection rule immediately to stop any further false positives.

  4. D

    Create an exclusion for the benign application to prevent it from being flagged while fine-tuning the rule.

  5. E

    Update the rule to include additional context, such as file hash or process behavior, to improve detection accuracy.

Show answer and explanation

Correct answers: A, B, D, E

Explanation

When troubleshooting detection rules, it's important to first validate the rule's logic and conditions to identify any misconfigurations or overly broad definitions. Reviewing event logs provides insights into why the rule was triggered. Creating exclusions for benign applications ensures operational continuity without compromising the security posture. Finally, refining the rule with more specific criteria ensures accurate detection while minimizing false positives. Disabling the rule entirely should only be a last resort if the issue cannot be resolved promptly.

  • A. Correct.

    Verifying the conditions and logic of the detection rule is critical to ensure the rule is functioning as intended and not overly broad, which could lead to false positives.

  • B. Correct.

    Reviewing the Secure Endpoint event logs will help identify whether the flagged application matches the rule's criteria, confirming whether the rule is misconfigured.

  • C. Incorrect.

    Disabling the rule immediately is not the best approach as it could leave the organization vulnerable to threats the rule was designed to detect.

  • D. Correct.

    Creating an exclusion for the benign application allows operations to continue without disruption while the rule is being refined.

  • E. Correct.

    Updating the rule with additional context, such as file hash or behavior, can help improve its precision and reduce false positives.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam