Q25Content Security
A Cisco ESA network administrator has been assigned to use a newly installed service to help create a policy based on the reputation verdict. During testing, it is found that Cisco ESA is not dropping files with an undetermined verdict. What is causing this issue?
← → navigate · a answer
Community votes
Discussion · 20
20
I see B as a possibility
Quarantine is only for unrecognized files. When the file is undetermined, the reputation score is checked. Reputation 1-59: Deliver file / Reputation 60-100: Block file
So B seems right.
See - Figure 1. Advanced Malware Protection Workflow for Public-Cloud File Analysis Deployments
https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_chapter_010000.html
7
I am sure it is D. The policy was created to disable file analysis.
When the reputation is unclear = undetermined, the file should be sent for file analysis. That is not happening, so the file is not dropped.
4
Answer B
guys, please refer to Figure 1. Advanced Malware Protection Workflow for Public-Cloud File Analysis Deployments
The undetermined verdict with score 1- 59 will deliver the file to the user
The undetermined verdict with score 60- 100 will block the file
So answer C, the reputation score is above the threshold is correct !
https://www.cisco.com/c/dam/en/us/td/i/400001-500000/410001-420000/415001-416000/415734.tif/_jcr_content/renditions/415734.jpg
3
The correct answer is B (it took me a while to understand that)
There is a difference between "Undetermined" (from the question), and "Unrecognized".
Undetermined - It checks the file score (Which is in the question - Right answer - B).
Unrecognize - Push file for analysis (Answer D - which is wrong here).
https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_chapter_010000.html
B 3
Selected Answer: B
Check the flow diagram, it's B
https://www.cisco.com/c/en/us/td/docs/security/esa/esa14-2-3/User_Guide/b_ESA_Admin_Guide_14-2-3/b_ESA_Admin_Guide_12_1_chapter_010001.html#con_1809437
2
it is the reputation of the file that is being inspected, for an indeterminate verdict a score is set from 0 to 100 - C, its correct.
https://www.cisco.com/c/en/us/td/docs/security/ces/user_guide/esa_user_guide/b_ESA_Admin_Guide_ces_11_0/b_ESA_Admin_Guide_chapter_010000.pdf
2
Sorry for the typo, the answer is C
B 1
Selected Answer: B
https://www.cisco.com/c/en/us/td/docs/security/esa/esa11-0/user_guide_fs/b_ESA_Admin_Guide_11_0/b_ESA_Admin_Guide_chapter_010000.html
undetermined verdict below threshold on reputation score so delivered
B 1
Selected Answer: B
B looks right.
"undetermined verdict" is found right before scoring within the "Recognized File" process under reputational service.
once a file has undetermind verdict, there are only 2 options below, deliver or drop based on the reputation score.
for D, I am not sure if you can make a policy to disable fily analysis service....you can enable or disable the service optionally....
B 1
Selected Answer: B
How are SenderBase Reputation Scores (SBRS) determined, and what do they mean?
SenderBase scores are assigned to IP addresses based on a mix of factors, including email volume and reputation.
Reputation scores in SenderBase may range from -10 to +10, reflecting the chance that a sending IP address is trying to send spam. Highly negative scores indicate senders who are very likely to be sending spam; highly positive scores indicate senders who are unlikely to be sending spam.
1
Sorry, typo again, final answer is B Confirmed!
the old version of the doc shown below
https://www.cisco.com/c/en/us/td/docs/security/wsa/wsa11-0/user_guide/b_WSA_UserGuide/b_WSA_UserGuide_chapter_010001.html
1
C is the right answer. Cheers
D 1
Selected Answer: D
Maybe the “newly installed service” in this Q mentions Advanced Malware Protection (AMP), which can be used together with ESA. AMP provides stronger protection across the attack continuum.
1
If the file is known to the reputation service but there is not enough information for a definitive verdict, the reputation service returns a reputation score based on file traits such as threat fingerprint and behavioral analysis. If this score meets or exceeds the configured reputation threshold, the appliance applies the action you have
configured in the mail policy for files that contain malware .
A 1
Selected Answer: A
In the scenario described in the question, the issue is that the Cisco ESA is not dropping files that have an undetermined verdict. The undetermined verdict means that the reputation service did not have enough information to determine the file's reputation score. When the Cisco ESA encounters a file with an undetermined verdict, it checks the message filter to decide what action to take. If the message filter is configured to quarantine the message, then the file will be sent to the quarantine area, even if the reputation score is undetermined.
B 1
Selected Answer: B
Option B is correct.
The figure 1 above on the already shared link explains it.
1
I would choose D.
When a file's reputation verdict is undetermined, it means the Cisco ESA's file analysis feature could not figure out the file's reputation. In a typical setup, the Cisco ESA would be able to drop or quarantine files based on their reputation verdicts. However, if the policy is set to disable file analysis, it means the Cisco ESA is not analyzing the files and therefore cannot drop them based on their reputation.
Therefore, option D is the most likely cause of the issue described in the scenario.
1
It should be this one:
https://www.cisco.com/c/en/us/td/docs/security/ces/user_guide/esa_user_guide_14-0/b_ESA_Admin_Guide_ces_14-0/b_ESA_Admin_Guide_12_1_chapter_010001.html
D 1
Selected Answer: D
From the Cisco documentation, files with an undetermined verdict (i.e., "Unscannable" or files without enough reputation data) can be set to either be sent for more analysis or quarantined. If no policy action is configured to quarantine or analyze those files, they may be released to the recipient.
Given that, the most likely reason for the issue you are describing is:
D. The policy was created to disable file analysis.
Turning off file analysis would stop undetermined verdicts from being processed properly, which would cause files not to be dropped or quarantined as expected.
https://www.cisco.com/c/en/us/td/docs/security/esa/esa14-2-3/User_Guide/b_ESA_Admin_Guide_14-2-3/b_ESA_Admin_Guide_12_1_chapter_010001.html#con_1809437
D 1
Selected Answer: D
D is the correct answer