Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 5Objective 1

5.1 Cisco AMP for Networks, Cisco AMP for Endpoints, and Cisco AMP for Content Security (Cisco ESA, and Cisco WSA) CCIE-SECURITY Practice Questions (Page 7)

Part of the 5.0 Advanced Threat Protection and Content Security domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 59 practice questions to prepare you well beyond it. (estimate)

59questions here
12free pages
10concepts
20%of the exam

Questions 31–35

  1. 31application · medium

    An organization is deploying Cisco AMP for Endpoints to protect a mix of Windows and macOS laptops. The security team wants to ensure that if a user disconnects from the corporate VPN, the endpoint still receives protection and can send telemetry to the cloud. They also want to prevent a specific application from being installed on all endpoints. Which deployment and policy settings should be used?

    Select an answer first
  2. 32expert · hard

    A security administrator is configuring AMP for Networks to protect against ransomware. They want to block files that are known to be ransomware, but they also want to allow a specific file that is used by a legitimate internal application, even though the file's reputation is 'malicious' due to a false positive. The administrator has the file's SHA-256 hash. What is the best way to achieve this?

    Select an answer first
  3. 33application · medium

    A company uses Cisco ESA for email security. They want to leverage AMP to analyze email attachments that are not yet known to the reputation service. The security team requires that if a file is later found malicious, the original email should be automatically removed from user mailboxes. Which configuration should be implemented?

    Select an answer first
  4. 34application · medium

    A company is integrating Cisco WSA with AMP for Content Security. They want to block downloads of files that are known malicious, but for unknown files they want to allow the first download and then block subsequent downloads if the file is later found malicious. What is the correct configuration approach?

    Select an answer first
  5. 35application · medium

    A security analyst is investigating a potential malware outbreak in the organization. They notice that a file was allowed by AMP for Endpoints three days ago, but now the AMP threat intelligence feed has updated the file's reputation to malicious. The analyst wants to identify all endpoints that have this file and remediate them. Which feature should the analyst use in the AMP for Endpoints console?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.