
CCIE Security
Domain 5Objective 1
5.1 Cisco AMP for Networks, Cisco AMP for Endpoints, and Cisco AMP for Content Security (Cisco ESA, and Cisco WSA) CCIE-SECURITY Practice Questions (Page 9)
Part of the 5.0 Advanced Threat Protection and Content Security domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 59 practice questions to prepare you well beyond it. (estimate)
59questions here
12free pages
10concepts
20%of the exam
Questions 41–45
- 41
An organization is deploying AMP for Endpoints to 1,000 devices. They want to ensure that the connectors are always up to date and that the security team can quickly see which endpoints are not communicating with the AMP cloud. Which feature should they use?
Select an answer first - 42
A network administrator is configuring AMP for Networks to detect and block malware. They want to ensure that if a file is initially unknown and later found malicious, the network is protected retroactively. Which feature should they enable?
Select an answer first - 43
An administrator is troubleshooting an AMP for Networks deployment where the appliance is not receiving traffic. The appliance is connected to a switch port configured as a SPAN destination. The administrator expects to see traffic in the dashboard, but no data is shown. What is the most likely cause?
Select an answer first - 44
A security analyst is using AMP for Endpoints to investigate a potential advanced persistent threat. They notice that a file with a low reputation score was executed on several endpoints, but the file was not blocked because the policy was set to 'detect'. The analyst wants to prevent further execution of this file across the organization. What is the most efficient action?
Select an answer first - 45
A company uses Cisco ESA with AMP for Content Security. They are experiencing a high number of false positives where legitimate emails are being quarantined because the attachments are unknown and later deemed malicious. The security team wants to reduce false positives while still maintaining protection. What should they do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.