
CiscoCertified Network Professional Security
Domain 5Objective 1
5.1 Describe Endpoint Protection Platforms (EPP) and Endpoint Detection and Response (EDR) Solutions 350-701 Practice Questions (Page 4)
Part of the Endpoint Protection and Detection domain, which accounts for 15% of the 350-701 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–2 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
4concepts
15%of the exam
Questions 16–20
- 16
A large enterprise is evaluating endpoint security solutions. They have a mature SOC that performs proactive threat hunting and a strict change-management process that requires minimal disruption to business operations. They need to block known malware and also detect sophisticated, fileless attacks. Which solution would best meet these needs?
Select an answer first - 17
A security analyst is investigating an alert about a suspicious process that has been running for several days. The process is not flagged by the EPP, and the analyst needs to determine if it is malicious. The analyst has access to an EDR console. Which action would provide the most useful information?
Select an answer first - 18
An EDR solution has detected a suspicious process on an endpoint. Which of the following actions is most characteristic of an EDR's response capability?
Select an answer first - 19
Which of the following is a core capability of an Endpoint Protection Platform (EPP)?
Select an answer first - 20
How do EPP and EDR solutions complement each other when integrated?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-701” is a trademark of its owner, used for identification only.