Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Security

Domain 5Objective 6

5.6 Interpret Cisco Secure Endpoint Malware Detection Events 350-701 Practice Questions (Page 5)

Part of the Endpoint Protection and Detection domain, which accounts for 15% of the 350-701 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–2 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)

32questions here
7free pages
8concepts
15%of the exam

Questions 21–25

  1. 21foundation · easy

    Which piece of information is typically included in a Cisco Secure Endpoint malware detection event to uniquely identify the malicious file?

    Select an answer first
  2. 22application · medium

    An analyst is investigating a Cisco Secure Endpoint event for a file named 'report.pdf.exe'. The event is enriched with threat intelligence showing it is associated with the 'APT29' threat actor and has been observed in a campaign targeting the healthcare sector. The severity is 8. What does this enrichment add to the analyst's understanding?

    Select an answer first
  3. 23expert · hard

    A security team is investigating a series of Cisco Secure Endpoint events. Event A: a trojan with severity 6 on a user workstation. Event B: a spyware with severity 7 on a file server. Event C: a ransomware with severity 9 on a backup server. The team has limited resources and can only fully investigate one event immediately. Which event should they prioritize?

    Select an answer first
  4. 24foundation · easy

    Which detection technology is most effective at identifying previously unknown malware by analyzing its actions rather than its code?

    Select an answer first
  5. 25application · medium

    An analyst is triaging multiple Cisco Secure Endpoint events. Event 1: a trojan with severity 8 on a domain controller. Event 2: a PUA with severity 4 on a marketing workstation. Event 3: a spyware with severity 6 on a finance workstation. Which event should the analyst investigate first?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-701” is a trademark of its owner, used for identification only.