Exempt Custom Application in Cisco Secure Endpoint
An organization created a custom application that is being flagged by Cisco Secure Endpoint. The application must be exempt from being flagged. What is the process to meet the requirement?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Creating an exclusion for a false positive in Cisco Secure Endpoint requires providing the SHA-256 hash of the application to the allowed applications list.
To exempt a custom application from being flagged by Cisco Secure Endpoint, you must add its hash to the allowed applications. This page explains why precalculating the SHA-256 hash is the correct method for creating an exclusion.
Choosing the custom detection list (Option D) is a common mistake because the custom detection list is primarily used to assign specific dispositions like malware, rather than simply exempting an application.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option C is correct because when a legitimate custom application is incorrectly flagged as malware (a false positive) by Cisco Secure Endpoint, the standard remediation is to create an exclusion. To do this securely and accurately, administrators precalculate the SHA-256 hash value of the application's executable and add it to the allowed applications or exclusions policy. This ensures the engine ignores the file based on its unique cryptographic signature.Why the Other Options Are Wrong
Option A is incorrect because "information-store paths" is not a valid feature or method for exempting applications in Cisco Secure Endpoint. Option B is incorrect because the DFC (Device Flow Correlation) list is unrelated to application exemption or malware dispositioning. Option D is incorrect because the custom detection list is used to force a specific disposition (e.g., treating a benign file as malware), whereas allowing an exempted application is handled via the exclusions or allowed applications list.Community Comment Notes
Commenters agreed that providing the SHA-256 hash is the correct approach for creating a process exclusion. As artilling noted, "You can provide an absolute path and/or a SHA-256 of the process executable when creating a Process exclusion." Another user clarified the distinction of the custom detection list, noting it is used to "treat a file as if the AMP cloud assigned a malware disposition" rather than simply exempting it.Official Reference
Exam Strategy
When dealing with false positives in Cisco Secure Endpoint, look for options involving SHA-256 hashes and exclusions or allowed applications. Avoid options referencing detection lists, which are typically used for blocking or assigning malware dispositions.