Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 5Objective 1

5.1 Cisco AMP for Networks, Cisco AMP for Endpoints, and Cisco AMP for Content Security (Cisco ESA, and Cisco WSA) CCIE-SECURITY Practice Questions (Page 6)

Part of the 5.0 Advanced Threat Protection and Content Security domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 59 practice questions to prepare you well beyond it. (estimate)

59questions here
12free pages
10concepts
20%of the exam

Questions 26–30

  1. 26expert · hard

    A security architect is designing a defense-in-depth strategy. They have deployed AMP for Endpoints with Exploit Prevention and Behavioral Protection. However, they are concerned about a specific exploit that uses a legitimate system tool (e.g., PowerShell) to execute malicious scripts. The exploit is not a memory-corruption attack and does not involve process injection. Which additional AMP feature should be enabled to detect and block this type of attack?

    Select an answer first
  2. 27expert · hard

    An incident responder is using the AMP for Endpoints console to investigate a widespread malware infection. The malware has been detected on multiple endpoints, and the responder wants to see all endpoints that have the same file SHA-256 hash. They also want to know the first time the file was seen on each endpoint. Which console feature provides this information?

    Select an answer first
  3. 28expert · hard

    A company is using Cisco ESA with AMP for Content Security. They have a policy that allows emails with unknown attachments to be delivered, but they want to automatically remove the email from the user's mailbox if the attachment is later found malicious. They also want to notify the user that the email was removed. Which configuration should be used?

    Select an answer first
  4. 29expert · hard

    A security operations center (SOC) is using AMP for Networks and AMP for Endpoints. They receive an alert that a file was detected as malicious by the AMP for Networks sandbox. The file was previously allowed on the network. The SOC wants to identify which endpoints may have been affected by this file and remediate them. Which approach should be used?

    Select an answer first
  5. 30expert · hard

    A network administrator is troubleshooting an issue where AMP for Networks is not blocking files that are known to be malicious. The administrator has verified that the policy is set to 'Block' and the appliance is in inline mode. The AMP for Networks dashboard shows that the appliance is receiving traffic. What is the most likely cause of this issue?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.