
CiscoCertified Network Professional Security
Domain 5Objective 6
5.6 Interpret Cisco Secure Endpoint Malware Detection Events 350-701 Practice Questions (Page 5)
Part of the Endpoint Protection and Detection domain, which accounts for 15% of the 350-701 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–2 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
8concepts
15%of the exam
Questions 21–25
- 21
Which piece of information is typically included in a Cisco Secure Endpoint malware detection event to uniquely identify the malicious file?
Select an answer first - 22
An analyst is investigating a Cisco Secure Endpoint event for a file named 'report.pdf.exe'. The event is enriched with threat intelligence showing it is associated with the 'APT29' threat actor and has been observed in a campaign targeting the healthcare sector. The severity is 8. What does this enrichment add to the analyst's understanding?
Select an answer first - 23
A security team is investigating a series of Cisco Secure Endpoint events. Event A: a trojan with severity 6 on a user workstation. Event B: a spyware with severity 7 on a file server. Event C: a ransomware with severity 9 on a backup server. The team has limited resources and can only fully investigate one event immediately. Which event should they prioritize?
Select an answer first - 24
Which detection technology is most effective at identifying previously unknown malware by analyzing its actions rather than its code?
Select an answer first - 25
An analyst is triaging multiple Cisco Secure Endpoint events. Event 1: a trojan with severity 8 on a domain controller. Event 2: a PUA with severity 4 on a marketing workstation. Event 3: a spyware with severity 6 on a finance workstation. Which event should the analyst investigate first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-701” is a trademark of its owner, used for identification only.