Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 5Objective 1

5.1 Cisco AMP for Networks, Cisco AMP for Endpoints, and Cisco AMP for Content Security (Cisco ESA, and Cisco WSA) CCIE-SECURITY Practice Questions (Page 8)

Part of the 5.0 Advanced Threat Protection and Content Security domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 59 practice questions to prepare you well beyond it. (estimate)

59questions here
12free pages
10concepts
20%of the exam

Questions 36–40

  1. 36application · medium

    A network administrator is deploying Cisco AMP for Networks in a high-availability pair. They want to ensure that if the primary appliance fails, the secondary appliance can take over without interrupting traffic inspection. They also need to be able to generate a report showing the number of files blocked by AMP over the last month. Which deployment mode and reporting feature should be used?

    Select an answer first
  2. 37application · medium

    A company has deployed Cisco AMP for Endpoints on all Windows workstations. They want to protect against memory-corruption attacks that exploit vulnerabilities in applications. They also want to ensure that if a new process tries to inject code into another process, it is blocked. Which two protection features should be enabled?

    Select an answer first
  3. 38application · medium

    A network administrator notices that the AMP for Networks appliance is not blocking any files, even though the policy is set to block malicious files. The administrator checks the AMP for Networks dashboard and sees that the appliance is receiving traffic. What is the most likely cause of this issue?

    Select an answer first
  4. 39application · medium

    A company wants to allow a specific internal application to download a file that is currently flagged as malicious by AMP for Networks. The file is used by the application and is known to be safe. The security team wants to ensure that this file is not blocked for any user. What should be configured in the AMP for Networks policy?

    Select an answer first
  5. 40application · medium

    A company is deploying Cisco AMP for Networks in inline mode at the internet edge. The security team wants to block known malware files immediately while allowing unknown files to be sandboxed for analysis. They also need to ensure that files from a trusted internal file server are never blocked. Which configuration should be applied?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.