正解:C
The described SD-WAN security feature is Cisco Advanced Malware Protection. Cisco Catalyst SD-WAN security documentation identifies AMP as the component that uses global threat intelligence, file reputation, advanced sandboxing, real-time malware blocking, and continuous analysis of file activity across the extended network. That wording maps directly to the question. AMP focuses on detecting malicious files, analyzing unknown files, blocking threats, and performing retrospective analysis if a file is later determined to be malicious. An intrusion prevention system inspects traffic for exploit signatures and known attack behaviors; it does not primarily provide file sandboxing and retrospective malware analysis. Enterprise Firewall with Application Awareness delivers stateful firewall control and application visibility. DNS-layer security, commonly integrated through Cisco Umbrella, blocks threats based on DNS requests before connections are made. The feature that specifically combines global threat intelligence, sandboxing, and continuous file analysis is AMP. Reference topics: Cisco Catalyst SD-WAN security, Advanced Malware Protection, UTD, file reputation, file analysis, sandboxing.