Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Security

Domain 5Objective 6

5.6 Interpret Cisco Secure Endpoint Malware Detection Events 350-701 Practice Questions (Page 3)

Part of the Endpoint Protection and Detection domain, which accounts for 15% of the 350-701 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–2 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)

32questions here
7free pages
8concepts
15%of the exam

Questions 11–15

  1. 11application · medium

    An analyst is reviewing a Cisco Secure Endpoint event for a file named 'malware.exe'. The event status shows 'Quarantined'. The analyst has verified that the file is indeed malicious and has been contained. What is the next step in the event lifecycle?

    Select an answer first
  2. 12application · medium

    A Cisco Secure Endpoint event shows a file named 'system_update.exe' detected as ransomware with severity 9. The file has encrypted several files on the endpoint. What is the most immediate remediation action?

    Select an answer first
  3. 13foundation · easy

    Which detection technology in Cisco Secure Endpoint uses known patterns of malicious code to identify malware?

    Select an answer first
  4. 14foundation · easy

    When triaging malware detection events, how should an analyst use the severity level?

    Select an answer first
  5. 15foundation · easy

    When triaging correlated malware events, which factor should be considered to prioritize response?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-701” is a trademark of its owner, used for identification only.