Be able to describe how the AMP for Endpoints Connector is deployed, how it integrates with Threat Grid for file analysis, and what IOCs it reports. The single most important thing is knowing the required console configuration steps to point AMP at a Threat Grid appliance.
Start practicing
Endpoint Protection and Detection — choose a session length
Free · No account required
Domain overview
This domain covers Cisco endpoint security, centered on AMP for Endpoints (now Secure Endpoint) and its integration with Threat Grid, plus broader endpoint detection concepts. Questions test deployment methods, IOC detection, console configuration, and matching security technologies to their functions. It is roughly 10% of the SCOR 350-701 exam and is tested through multiple-choice, multi-select, and matching items.
Exam objectives
Deploying the AMP for Endpoints Connector on Windows via methods like group policy, SCCM, and command line
Configuring AMP for Endpoints to submit files to a Threat Grid appliance for analysis
Identifying indicators of compromise such as file hashes and network connections that AMP detects
Matching endpoint technologies like AMP, Umbrella, and Firepower to their primary security functions
Confusing AMP for Endpoints with AMP for Networks or Umbrella, which are separate products with different deployment and console scopes.
Assuming Threat Grid integration needs no separate appliance registration or API key configuration in the AMP console.
Treating all file analysis as cloud-only, missing that on-premises Threat Grid appliances can be selected as the analysis engine.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A security administrator notices that several endpoints in the finance department are exhibiting unusual network behavior, including connections to known malicious IP addresses. The administrator has deployed Cisco Secure Endpoint (formerly AMP for Endpoints) with TETRA and has enabled the built-in firewall. What is the best course of action to quickly identify the root cause and contain the threat?
2An organization wants to prevent malware from executing on endpoints by using a file reputation service. Which Cisco technology provides cloud-based file reputation and analysis for endpoint protection?
3A company is deploying Cisco Secure Endpoint and wants to ensure that endpoints are protected against zero-day exploits. Which two features should be enabled to provide this protection? (Choose two.)
4A company with 5,000 endpoints is using Cisco Secure Endpoint. The security team receives an alert that a specific file (SHA256: 8f4a...b2c) has been detected as malware on 10 endpoints. The file has been quarantined on those endpoints. The team wants to ensure that no other endpoints in the organization have this file. Which feature should be used to locate the file across all endpoints?
5Which TWO configuration steps are required to enable Cisco AMP for Endpoints to use the Threat Grid appliance for file analysis?
6A security engineer is deploying Cisco AMP for Endpoints to protect against malware. The company wants to block all executables from running in the Downloads folder except those signed by a specific trusted publisher. Which policy configuration should the engineer use?
7Which THREE of the following are capabilities of Cisco Threat Response (CTR) that integrate with endpoint telemetry for accelerated detection and response?
8Refer to the exhibit. A network administrator configured IP Source Guard and DHCP Snooping on a switch. A host connected to GigabitEthernet0/2 with MAC address 0050.7966.6801 has been assigned IP 192.168.1.10 via DHCP. The host now tries to use IP 192.168.1.20. What will happen?
9Drag and drop the steps to configure a site-to-site IPsec VPN on a Cisco ASA into the correct order.
10Drag and drop the steps to configure a Cisco ASA for remote access VPN using AnyConnect in the correct order.
11Match each security technology to its primary function.
12Match each threat type to its definition.
13A company wants to deploy Cisco AMP for Endpoints to protect against advanced malware. Which best practice should be followed when configuring the policy for the first time?
14A security team is designing an endpoint protection strategy for a mix of Windows and macOS endpoints. They want to use Cisco AMP for Endpoints with centralized management. Which deployment approach minimizes administrative overhead?
15During a ransomware attack, an endpoint protected by AMP for Endpoints successfully blocked the ransomware file. Which AMP policy action was likely applied?
16An analyst reviews an AMP for Endpoints event where a file was detected as malware but later determined to be a false positive. The analyst wants to prevent this file from being flagged in the future. What is the recommended action?
17A company uses Cisco AMP for Endpoints and also deploys Cisco Firepower Next-Generation Firewall (NGFW) with AMP integration. The security team wants to see endpoint detections in the Firepower Management Center (FMC). What must be configured to enable this integration?
18An incident responder is analyzing an endpoint that was compromised despite AMP for Endpoints being deployed. The AMP logs show the malware file had a disposition of 'Unknown' shortly before compromise, but later changed to 'Malicious' after cloud analysis. What is the most likely reason the file was not blocked initially?
19Which THREE are recommended best practices for deploying Cisco AMP for Endpoints in a large enterprise?
20Which TWO indicators of compromise (IOCs) can Cisco AMP for Endpoints detect and alert on?
21Which TWO actions can be taken on a malicious file detected by Cisco AMP for Endpoints?
22Refer to the exhibit. The file invoice.pdf was determined to be malicious by the AMP cloud, yet the endpoint allowed it to execute. What is the most likely reason?
23Refer to the exhibit. What happened to the file 'crack.exe'?
24A network administrator notices that an endpoint running the AMP connector is not sending events to the cloud. The connector status shows 'Connected' in the AMP console. What is the most likely cause?
25A security engineer wants to implement file reputation analysis using Cisco AMP for Endpoints. The policy must block files that are known to be malicious in the cloud and quarantine unknown files for further analysis. Which AMP policy configuration achieves this?
26A company uses Cisco Umbrella to block malicious domains. An endpoint user reports that they cannot access a legitimate business website. The website resolves to a domain that is not on any block list. What is the most likely cause?
27An organization wants to deploy AMP for Endpoints in an offline environment where endpoints cannot connect to the internet. Which deployment option is appropriate?
28A security analyst sees multiple AMP events for 'Trojan.Generic.37283212' on several endpoints. After updating the AMP signatures, the detection still occurs. What is the best next step to reduce false positives?
29Which TWO of the following are required for successful registration of an AMP for Endpoints connector with the cloud?
30Which THREE of the following are indicators of compromise (IOCs) that can be detected by Cisco AMP for Endpoints?
31Based on the exhibit, what does the 'Isolated: Yes' status indicate?
32A network security engineer needs to block malicious file downloads on endpoints regardless of the user's location. Which Cisco solution should be integrated with the company's existing endpoint protection platform to achieve cloud-delivered threat intelligence?
33An organization has deployed Cisco AMP for Endpoints and wants to automatically isolate a host from the network when a high-severity malware detection occurs. Which integration must be configured to enable this automated response?
34A security analyst observes that one endpoint is generating Alerts of type 'Trojan' in Cisco AMP, but other identical endpoints on the same software version show no issues. After verifying that the signature versions are consistent, what is the most likely cause of the discrepancy?
35A SOC analyst notices that after deploying Cisco AMP for Endpoints, some legitimate business software is being blocked by the Exploit Prevention engine. What is the recommended action to allow this software while maintaining maximum security?
36Which component of Cisco AMP for Endpoints is responsible for preventing the execution of known malware by checking files against a continuously updated cloud database before they run?
37Which TWO of the following are capabilities of Cisco Orbital?
38Which THREE of the following are valid methods to deploy Cisco AMP for Endpoints Connector on Windows endpoints?
39Which TWO of the following are indicators of compromise (IOCs) that can be detected by Cisco AMP for Endpoints?
40A network engineer is troubleshooting an endpoint that failed to receive policy updates from the Cisco AMP cloud. The endpoint shows 'Out-of-Date' in the AMP console. The engineer verifies that the endpoint has outbound HTTPS access to the AMP cloud. What additional step should the engineer take to resolve the issue?
41An organization is deploying Cisco Secure Endpoint (AMP) for the first time in a Windows environment. The security team wants to ensure that any file executed from a USB drive is automatically scanned and blocked if malicious. Which policy feature should be enabled to achieve this?
42A multinational company plans to deploy Cisco AMP for Endpoints across 10,000 endpoints in geographically diverse offices. The security team is concerned about WAN bandwidth usage when endpoints communicate with the AMP cloud. Which design approach best minimizes cloud communication traffic while maintaining effective protection?
43An incident responder uses the Cisco AMP for Endpoints console to investigate a potential malware outbreak. The endpoint shows multiple files with high prevalence and cloud verdicts of 'unknown'. The responder wants to quickly identify files that were executed from a malicious parent process. Which console feature best assists this analysis?
44Which THREE actions should a security engineer take when configuring a Cisco AMP for Endpoints policy to minimize false positives while maintaining strong protection?
45Which TWO are required to successfully deploy Cisco AMP for Endpoints in a Windows domain environment with Group Policy?
46An organization is deploying Cisco Secure Endpoint (AMP) in a high-security environment where endpoints are air-gapped from the internet. The security team needs to maintain up-to-date threat intelligence without direct cloud access. They have a dedicated local server that can download feeds from the AMP cloud once and distribute to endpoints. The server runs the AMP Private Cloud software. However, after installation, endpoints are not receiving updates. The team verifies that the Private Cloud server can reach the AMP cloud via a managed proxy. The endpoints can communicate with the Private Cloud server on TCP 443. What is the most likely cause of the update failure?
47A university IT team manages 1,000 macOS laptops for students using Cisco AMP for Endpoints. They receive reports that some students' laptops are running slowly and fans are spinning constantly. The team checks the AMP console and sees that these endpoints are performing constant file scans on user directories. The team suspects that the AMP scanning is causing high CPU usage. They want to optimize performance without compromising security. The laptops use the default AMP policy with real-time scanning enabled. What should the team do?
48Based on the exhibit, what is the most likely reason that traffic matching the AMP_block access-list is not being blocked?
49A company with 5000 endpoints uses Cisco Secure Endpoint (AMP) and Cisco ISE. Users report that legitimate software installations are being quarantined, causing delays. The security team receives many alerts for file executions. The AMP policy is set to "High Security" with "Block Unknown" enabled. Network traffic is monitored by Cisco Stealthwatch. The team wants to reduce operational overhead while maintaining security. What should they do?
50A security team has deployed Cisco Secure Endpoint (formerly AMP for Endpoints) connectors running in audit mode on 500 Windows servers. The team now wants to enforce a policy that will quarantine any file that the cloud verdict engine identifies as malicious within 30 seconds of execution. Which policy setting should they modify?
51A financial institution uses Cisco Secure Endpoint and wants to integrate it with Cisco Threat Response (CTR) to accelerate investigations. An analyst receives an alert about a suspicious file and wants to automatically enrich the investigation with endpoint telemetry, such as process lineage and network connections, without manually running queries. Which Cisco Secure Endpoint feature should the analyst leverage within CTR?
52A security operations team needs to query endpoint telemetry across thousands of Cisco Secure Endpoint connectors to hunt for indicators of compromise. They want to run SQL-like queries on live endpoint data without deploying additional agents. Which Cisco solution should they use?
53A security operations team at a hospital is using Cisco Secure Endpoint (formerly AMP for Endpoints) to protect clinical workstations. The team must ensure that when a clinician opens a document from a USB drive, the file is checked against Cisco Talos threat intelligence before it is allowed to execute, and that the check happens locally on the endpoint without sending the full file to the cloud. Which Cisco Secure Endpoint engine component performs this on-endpoint lookup using a cached copy of the Talos reputation database?
54A security operations team wants to automatically contain a compromised endpoint by blocking all network communication except for the Cisco Secure Endpoint cloud and the management console. The team is using Cisco Secure Endpoint (formerly AMP for Endpoints) and needs to enforce this containment without relying on network segmentation. Which feature should they use to achieve this?
55A financial services firm uses Cisco Secure Endpoint and Cisco SecureX. An analyst receives an alert that a spreadsheet opened on an accounting workstation spawned a command shell that attempted to reach an external IP address. The analyst wants to see, in a single view, the file trajectory of the spreadsheet, the process lineage on the endpoint, and any related threat intelligence from Talos. Which Cisco Secure Endpoint capability provides this correlated, single-pane investigative view?
56A security analyst is investigating a suspicious file that was executed on an endpoint protected by Cisco Secure Endpoint. The analyst wants to determine the file's lineage and all processes it spawned. Which Cisco Secure Endpoint feature provides this information?
57A security analyst is investigating a ransomware outbreak on several endpoints protected by Cisco Secure Endpoint. The analyst wants to identify the initial infection vector and the subsequent command-and-control (C2) domains contacted. Which Secure Endpoint console feature provides a unified timeline of file, network, and process events for a specific endpoint?
58A retail company is deploying Cisco Secure Endpoint on point-of-sale terminals running Windows 10. The security team wants the connector to automatically terminate a malicious process and quarantine the associated file when a high-severity detection occurs, without requiring an analyst to take action. Which policy configuration in Cisco Secure Endpoint accomplishes this?
59A network administrator is deploying Cisco Secure Endpoint connectors to Windows servers. The administrator needs to ensure that the connector can communicate with the Cisco cloud even when the server is behind a strict web proxy that requires authentication. Which connector configuration should be used?
60A university's security team uses Cisco Secure Endpoint to protect research workstations. A professor reports that an application used for genomic analysis is being repeatedly quarantined, disrupting research. The team verifies the application is legitimate and signed by a trusted vendor. The team wants to prevent future quarantine of this specific application while keeping all other protections active. What should the team configure in Cisco Secure Endpoint?
61A multinational corporation has deployed Cisco Secure Endpoint across 20,000 endpoints. The security operations center wants to reduce alert fatigue by ensuring that only high-fidelity detections trigger investigations. The team plans to use indicators of compromise (IOCs) and custom detections. Which two actions should the team take to improve detection fidelity? (Choose two.)
62A security analyst is using Cisco Secure Endpoint's device trajectory feature to investigate a suspicious process on a Windows endpoint. The analyst wants to identify the parent-child process relationships and the files accessed by the process. Which two actions can the analyst perform within the device trajectory view to achieve this? (Choose two.)
63A security administrator is deploying Cisco Secure Endpoint (AMP for Endpoints) connectors on a fleet of Windows servers. The administrator wants to ensure that the connectors automatically receive the latest policy updates and threat intelligence from the cloud without manual intervention. Which component of the Cisco Secure Endpoint architecture is responsible for this automatic synchronization?
64A security operations center (SOC) uses Cisco Secure Endpoint and wants to proactively hunt for indicators of compromise (IOCs) across all endpoints. The team needs to query running processes, loaded modules, and network connections on demand without disrupting endpoint operations. Which Secure Endpoint feature should they use?
Deep-dive questions
The most-searched questions in this domain — detailed explanations, worked examples, full answer breakdowns.
Be able to describe how the AMP for Endpoints Connector is deployed, how it integrates with Threat Grid for file analysis, and what IOCs it reports. The single most important thing is knowing the required console configuration steps to point AMP at a Threat Grid appliance.
The Courseiva 350-701 question bank contains 64 questions in the Endpoint Protection and Detection domain, covering the 10% of the exam attributed to this domain in the official Cisco blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Endpoint Protection and Detection domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included