Exempt Custom Application in Cisco Secure Endpoint

Configure Cisco Secure Endpoint integration with Secure Firewall Management Center
Answer Correct answer: C — Precalculate the hash value of the custom application and add it to the allowed applications.

An organization created a custom application that is being flagged by Cisco Secure Endpoint. The application must be exempt from being flagged. What is the process to meet the requirement?

  1. Configure the custom application to use the information-store paths.
  2. Add the custom application to the DFC list and update the policy.
  3. Precalculate the hash value of the custom application and add it to the allowed applications. Correct Answer
  4. Modify the custom detection list to exclude the custom application.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Creating an exclusion for a false positive in Cisco Secure Endpoint requires providing the SHA-256 hash of the application to the allowed applications list.

To exempt a custom application from being flagged by Cisco Secure Endpoint, you must add its hash to the allowed applications. This page explains why precalculating the SHA-256 hash is the correct method for creating an exclusion.

Choosing the custom detection list (Option D) is a common mistake because the custom detection list is primarily used to assign specific dispositions like malware, rather than simply exempting an application.

Community Discussion (3 comments)

artilling 👍 1 Selected: C
Correct Answer: C You can provide an absolute path and/or a SHA-256 of the process executable when creating a Process exclusion. If you specify both a path and SHA-256 then both conditions must be met for the process to be excluded. https://www.cisco.com/c/en/us/support/docs/security/amp-endpoints/213681-best-practices-for-amp-for-endpoint-excl.html A. "Configure the custom application to use the information-store paths." < Not absolute path
gwb 👍 1
yeah. my choice is also "C" FYI Custom Detection List:(File not network traffic) To treat a file as if the AMP cloud assigned a malware disposition, you can add the file to the custom detection list. Once added, subsequent detections of the file result in the device either allowing or blocking the file without reevaluating its disposition. You can use the clean list or custom detection list per file policy2.
Bubu3k 👍 2
C seems to be the closest match, but not sure https://video.cisco.com/detail/video/6038252112001

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option C is correct because when a legitimate custom application is incorrectly flagged as malware (a false positive) by Cisco Secure Endpoint, the standard remediation is to create an exclusion. To do this securely and accurately, administrators precalculate the SHA-256 hash value of the application's executable and add it to the allowed applications or exclusions policy. This ensures the engine ignores the file based on its unique cryptographic signature.

Why the Other Options Are Wrong

Option A is incorrect because "information-store paths" is not a valid feature or method for exempting applications in Cisco Secure Endpoint. Option B is incorrect because the DFC (Device Flow Correlation) list is unrelated to application exemption or malware dispositioning. Option D is incorrect because the custom detection list is used to force a specific disposition (e.g., treating a benign file as malware), whereas allowing an exempted application is handled via the exclusions or allowed applications list.

Community Comment Notes

Commenters agreed that providing the SHA-256 hash is the correct approach for creating a process exclusion. As artilling noted, "You can provide an absolute path and/or a SHA-256 of the process executable when creating a Process exclusion." Another user clarified the distinction of the custom detection list, noting it is used to "treat a file as if the AMP cloud assigned a malware disposition" rather than simply exempting it.

Official Reference

Exam Strategy

When dealing with false positives in Cisco Secure Endpoint, look for options involving SHA-256 hashes and exclusions or allowed applications. Avoid options referencing detection lists, which are typically used for blocking or assigning malware dispositions.

Related Analysis

← Back to 300-710 Study Guide