Which Policy Is Associated With an Access Control Policy for Malware Defense?
A software development company hosts the website https://dev.company.com for contractors to share code for projects they are working on with internal developers. The web server is on premises and is protected by a Cisco Secure Firewall Threat Defense appliance. The network administrator is worried about someone trying to transmit infected files to internal users via this site. Which type of policy must be associated with an access control policy to enable Cisco Secure Firewall Malware Defense to detect and block malware?
Community Votes
83% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests where each policy type attaches in Secure Firewall Management Center: an SSL (decryption) policy is associated with the access control policy itself, while a file policy is pinned to individual access control rules to drive Malware Defense.
Enabling Cisco Secure Firewall Malware Defense against infected files pushed to https://dev.company.com requires the traffic to be decrypted first, so the SSL policy is the policy associated with an access control policy. This page explains why the SSL policy is the answer and why the file policy, which attaches to access control rules, is the classic trap.
Choosing the file policy (B) because Malware Defense is delivered through file inspection, while missing that file policies are attached to access control rules and cannot decrypt the HTTPS session that carries the uploads.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
In Secure Firewall Management Center the access control policy is the policy-level container where an SSL (decryption) policy is selected, and Cisco's decryption guidance is explicit that traffic must be decrypted before intrusion, file, and malware inspection engines can evaluate it. The question deliberately gives the HTTPS URL https://dev.company.com because contractor code uploads travel inside TLS; with unbroken encryption the Threat Defense appliance sees only opaque bytes, so no file is ever handed to Malware Defense and no malware verdict or block action can occur. Associating an SSL policy with the access control policy also matches the wording used in the stem — "associated with an access control policy" is precisely how the decryption policy is attached in the FMC policy editor. The file policy that actually performs Malware Cloud Lookup and Block Malware is a rule-level artifact, so on its own it never satisfies the association described in the question. Option A is therefore the only choice that both matches the attachment point and makes encrypted malware detection possible.Why the Other Options Are Wrong
A file policy (B) is the engine that enables Malware Defense, but it is selected inside an access control rule whose action is Allow with a file policy — it is not associated with the access control policy, and it cannot decrypt a TLS session by itself, so the files on this HTTPS site would remain invisible to it. A network discovery policy (C) only gathers host, application, user, and network data for the network map and discovery events; it produces no file or malware verdicts. A prefilter policy (D) makes early, pre-ACL decisions such as tunnel and SSL handling, fastpath, and blocklist rules; it has no file inspection or malware blocking capability at all. The distinguishing phrase in the stem is "access control policy" rather than "access control rule" — only the SSL/decryption policy attaches at the policy level, which is what the question is asking for.Community Comment Notes
KISRUVEM framed the distinction cleanly: "You associate a file policy to an ACP rule. You associate an SSL policy to an ACP." tinyJoe took a metaperspective and asked why the HTTPS sample URL was included at all, arguing the author intended decryption to be the theme of the question — a strong hint that A is the intended answer. Silexis raised the fair counterpoint that the internal developers may reach the on-premises web server by a plaintext path, but the question's risk scenario is about files arriving over the published HTTPS site, so decryption still has to be in place for Malware Defense to see them. gwb picked the file policy with a malware rule, which is the reasoning behind the 17 minority votes and reflects the natural confusion between rule-level file inspection and policy-level decryption.Official Reference
Exam Strategy
When two options both look like Malware Defense plumbing, read the attachment point in the stem: "associated with an access control policy" means the SSL/decryption policy, while "associated with an access control rule" means the file policy. Any time the stem shows an https:// URL and asks about detecting files or malware, expect a decryption policy to be part of the intended answer.
Frequently Asked Questions
Why isn't the file policy the answer if Malware Defense uses file inspection?
File policies are attached to access control rules that allow traffic, not to the access control policy itself, and they cannot decrypt TLS. The question asks what is associated with the access control policy.
Does Malware Defense still need a file policy in addition to the SSL policy?
Yes. Decryption exposes the files, but the Allow rule must still reference a file policy with Malware Cloud Lookup and Block Malware so the files are actually inspected and blocked.