Which Policy Is Associated With an Access Control Policy for Malware Defense?

Answer Correct answer: A — An SSL policy is the policy associated with the access control policy so encrypted HTTPS file transfers to dev.company.com can be decrypted and inspected.

A software development company hosts the website https://dev.company.com for contractors to share code for projects they are working on with internal developers. The web server is on premises and is protected by a Cisco Secure Firewall Threat Defense appliance. The network administrator is worried about someone trying to transmit infected files to internal users via this site. Which type of policy must be associated with an access control policy to enable Cisco Secure Firewall Malware Defense to detect and block malware?

  1. SSL policy Correct Answer
  2. file policy
  3. network discovery policy
  4. prefilter policy

Community Votes

A
83%
B
17%

83% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests where each policy type attaches in Secure Firewall Management Center: an SSL (decryption) policy is associated with the access control policy itself, while a file policy is pinned to individual access control rules to drive Malware Defense.

Enabling Cisco Secure Firewall Malware Defense against infected files pushed to https://dev.company.com requires the traffic to be decrypted first, so the SSL policy is the policy associated with an access control policy. This page explains why the SSL policy is the answer and why the file policy, which attaches to access control rules, is the classic trap.

Choosing the file policy (B) because Malware Defense is delivered through file inspection, while missing that file policies are attached to access control rules and cannot decrypt the HTTPS session that carries the uploads.

Community Discussion (4 comments)

gwb 👍 5
My choice is "B". Malware Defense - file policy with rule.
Silexis 👍 1 Selected: B
I think this a very tricky one - Cisco is throwing to people. Let's divide the workflow: contractors are using SSL connection to upload code from Internet. It is true that without SSL Policy - you won't be able to see the files. Developers, on the other hand, are connected to the webserver which is "on premises", making me think that they wont use the Internet URL but another one which is accessible only from Internal - but passing through the FTD - this is why, without a Malware&File policy an SSL will be just useless (even though the no mistake will be actually A&B together)
tinyJoe 👍 1 Selected: A
It is a difficult choice, but I choose A. “via this site” indicates that the site probably has the ability to send and receive files. The file sending/receiving traffic should be encrypted. And just to be metaperspective, if B is the correct answer, why is it necessary to describe the HTTPS sample URL in the question? I assume it is because the author wanted to make decryption the theme of the question.
KISRUVEM 👍 4 Selected: A
I think it’s A. You don’t associate a file policy to an ACP. You associate a file policy to an ACP rule. You associate an SSL policy to an ACP. Yes, it’s also called a “decryption policy” in the GUI but the config guide still calls it an SSL Policy.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

In Secure Firewall Management Center the access control policy is the policy-level container where an SSL (decryption) policy is selected, and Cisco's decryption guidance is explicit that traffic must be decrypted before intrusion, file, and malware inspection engines can evaluate it. The question deliberately gives the HTTPS URL https://dev.company.com because contractor code uploads travel inside TLS; with unbroken encryption the Threat Defense appliance sees only opaque bytes, so no file is ever handed to Malware Defense and no malware verdict or block action can occur. Associating an SSL policy with the access control policy also matches the wording used in the stem — "associated with an access control policy" is precisely how the decryption policy is attached in the FMC policy editor. The file policy that actually performs Malware Cloud Lookup and Block Malware is a rule-level artifact, so on its own it never satisfies the association described in the question. Option A is therefore the only choice that both matches the attachment point and makes encrypted malware detection possible.

Why the Other Options Are Wrong

A file policy (B) is the engine that enables Malware Defense, but it is selected inside an access control rule whose action is Allow with a file policy — it is not associated with the access control policy, and it cannot decrypt a TLS session by itself, so the files on this HTTPS site would remain invisible to it. A network discovery policy (C) only gathers host, application, user, and network data for the network map and discovery events; it produces no file or malware verdicts. A prefilter policy (D) makes early, pre-ACL decisions such as tunnel and SSL handling, fastpath, and blocklist rules; it has no file inspection or malware blocking capability at all. The distinguishing phrase in the stem is "access control policy" rather than "access control rule" — only the SSL/decryption policy attaches at the policy level, which is what the question is asking for.

Community Comment Notes

KISRUVEM framed the distinction cleanly: "You associate a file policy to an ACP rule. You associate an SSL policy to an ACP." tinyJoe took a metaperspective and asked why the HTTPS sample URL was included at all, arguing the author intended decryption to be the theme of the question — a strong hint that A is the intended answer. Silexis raised the fair counterpoint that the internal developers may reach the on-premises web server by a plaintext path, but the question's risk scenario is about files arriving over the published HTTPS site, so decryption still has to be in place for Malware Defense to see them. gwb picked the file policy with a malware rule, which is the reasoning behind the 17 minority votes and reflects the natural confusion between rule-level file inspection and policy-level decryption.

Official Reference

Exam Strategy

When two options both look like Malware Defense plumbing, read the attachment point in the stem: "associated with an access control policy" means the SSL/decryption policy, while "associated with an access control rule" means the file policy. Any time the stem shows an https:// URL and asks about detecting files or malware, expect a decryption policy to be part of the intended answer.

Frequently Asked Questions

Why isn't the file policy the answer if Malware Defense uses file inspection?

File policies are attached to access control rules that allow traffic, not to the access control policy itself, and they cannot decrypt TLS. The question asks what is associated with the access control policy.

Does Malware Defense still need a file policy in addition to the SSL policy?

Yes. Decryption exposes the files, but the Allow rule must still reference a file policy with Malware Cloud Lookup and Block Malware so the files are actually inspected and blocked.

Related Analysis

← Back to 300-710 Study Guide