350-201 Question 159
Select 3A security analyst is investigating an issue where a detection rule in Cisco Secure Endpoint (formerly AMP for Endpoints) is not generating alerts for known malicious activity. After verifying that the rule is enabled and correctly configured, what should the analyst do next to troubleshoot the issue?
- A
Check if the endpoint agent is running and properly communicating with the Cisco Secure Endpoint cloud.
- B
Verify the endpoint's operating system version to ensure it is supported by Cisco Secure Endpoint.
- C
Examine the event logs to determine if the rule is processing traffic but failing to trigger alerts.
- D
Disable and re-enable the detection rule to force it to reapply.
- E
Ensure that the detection rule's priority level is set to 'High.'
Show answer and explanation
Correct answers: A, B, C
Explanation
When troubleshooting detection rules in Cisco Secure Endpoint, it is important to first ensure that the endpoint agent is functioning properly and communicating with the cloud. Next, verify that the endpoint's operating system is supported. Finally, analyzing event logs can provide insight into whether the detection rule is functioning as expected but failing to trigger alerts. These steps help isolate the root cause of the issue and ensure the detection rule operates correctly.
- A. Correct.
If the endpoint agent is not running or cannot communicate with the cloud, detection rules may not function properly. This is a critical step in troubleshooting the issue.
- B. Correct.
Unsupported operating system versions can cause detection rules or endpoint agents to fail. Ensuring compatibility is crucial.
- C. Correct.
Examining event logs can help determine whether the rule is being triggered but failing to generate an alert due to misconfiguration or other issues.
- D. Incorrect.
Disabling and re-enabling the rule is not a recommended troubleshooting step, as it does not address the root cause of the issue.
- E. Incorrect.
The priority level of the detection rule does not impact its ability to trigger alerts; it only affects how alerts are displayed and handled.