Symptom
On an SDWAN cEdge router configured for Advanced Malware Protection, a file with a disposition of unknown is passed, but the output of the "show utd engine standard cache file-inspection" displays an action code of 2 (DROP) for the file.
Conditions
This is observed with the show utd engine standard cache file-inspection output when a file has been inspected by AMP.
Workaround
The problem is cosmetic only with the output. The actual file is passed by the Unified Threat Defense (UTD) engine.