Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 5Objective 1

5.1 Cisco AMP for Networks, Cisco AMP for Endpoints, and Cisco AMP for Content Security (Cisco ESA, and Cisco WSA) CCIE-SECURITY Practice Questions (Page 10)

Part of the 5.0 Advanced Threat Protection and Content Security domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 59 practice questions to prepare you well beyond it. (estimate)

59questions here
12free pages
10concepts
20%of the exam

Questions 46–50

  1. 46expert · hard

    An organization is using Cisco WSA with AMP for Content Security. They have a requirement to block all downloads of files with a 'malicious' disposition, but they are concerned about the performance impact of sandboxing every unknown file. They want to minimize the number of files sent to the sandbox while still blocking known malware. What should they configure?

    Select an answer first
  2. 47expert · hard

    A security administrator is using the AMP for Endpoints console to investigate a detection. They see that a file was detected as malware on one endpoint, but the same file was allowed on another endpoint. The administrator suspects that the policies are different between the two groups. What should they do to confirm this?

    Select an answer first
  3. 48expert · hard

    An organization is deploying AMP for Networks in a high-availability pair. They want to ensure that if one appliance fails, the other can continue to block malicious files without interruption. Which deployment mode should they use?

    Select an answer first
  4. 49expert · hard

    A company is deploying AMP for Endpoints on a mix of Windows and macOS devices. They want to ensure that all endpoints receive the same protection policies, but they also need to apply different settings for macOS due to performance constraints. What is the best approach?

    Select an answer first
  5. 50expert · hard

    A security team is using AMP for Networks and AMP for Endpoints. They want to correlate threat intelligence across both platforms to identify if a file that was seen on the network has also been executed on any endpoints. Which approach should they use?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.