Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 5Objective 1

5.1 Cisco AMP for Networks, Cisco AMP for Endpoints, and Cisco AMP for Content Security (Cisco ESA, and Cisco WSA) CCIE-SECURITY Practice Questions (Page 5)

Part of the 5.0 Advanced Threat Protection and Content Security domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 59 practice questions to prepare you well beyond it. (estimate)

59questions here
12free pages
10concepts
20%of the exam

Questions 21–25

  1. 21application · medium

    A company is deploying Cisco AMP for Networks in inline mode at the internet edge. The security team wants to ensure that files that are initially unknown are not allowed to pass through to users while the sandbox analysis is in progress. They also want to receive an alert if a file that was previously allowed is later determined to be malicious. Which two configurations must be combined to meet these requirements?

    Select an answer first
  2. 22application · medium

    An administrator is using the AMP for Endpoints console to investigate a detection on a single endpoint. They want to see the full timeline of events leading up to the detection, including the file's origin and any network connections made. Which view should the administrator use?

    Select an answer first
  3. 23application · medium

    A company uses Cisco ESA with AMP for Content Security. They want to ensure that if a user clicks a link in an email that leads to a malicious file download, the download is blocked by the WSA. Which integration should be configured?

    Select an answer first
  4. 24application · medium

    A security team is evaluating AMP for Networks to detect zero-day malware. They want to ensure that files that are not known to the reputation service are sent to the sandbox for analysis. They also want to receive a notification if the sandbox determines that a file is malicious after it has already been allowed. Which feature set should they enable?

    Select an answer first
  5. 25expert · hard

    A large enterprise is deploying AMP for Endpoints across 10,000 endpoints. They have a mix of Windows, macOS, and Linux servers. The security team wants to ensure that all endpoints are protected even if they are not connected to the corporate network for long periods. They also want to minimize the administrative overhead of managing the connectors. Which deployment model should be chosen?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.