
CiscoCertified Network Professional Security
Domain 5Objective 5
5.5 Configure Endpoint Antimalware Protection Using Cisco Secure Endpoint 350-701 Practice Questions (Page 6)
Part of the Endpoint Protection and Detection domain, which accounts for 15% of the 350-701 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–2 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
8concepts
15%of the exam
Questions 26–29
- 26
A company has a group of endpoints that frequently run custom in-house applications. These applications are not known to the AMP cloud and are sometimes flagged as malicious. The security team wants to prevent these false positives while still protecting against real threats. What should be configured in the policy?
Select an answer first - 27
A security analyst notices a retrospective alert for a file that was initially allowed but later determined to be malicious. The analyst needs to identify all endpoints that executed this file and understand the file's behavior over time. Which feature should the analyst use?
Select an answer first - 28
A security team needs to provide evidence to auditors that the antimalware policy was updated and that specific endpoints were isolated during a security incident. Which feature should be used to retrieve this information?
Select an answer first - 29
A security manager needs to verify that all endpoints are running the latest connector version and have the expected antimalware policy applied. Which feature should be used to get this information?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to 350-701
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-701” is a trademark of its owner, used for identification only.