These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.
Start Scenario PracticeRefer to the exhibit. A network administrator is troubleshooting device tracking on a Cisco switch. The output shows two devices in VLAN 100. The switch is configured with IPv6 first-hop security features. The administrator notices that the device with MAC address aaaa.bbbb.cccc is not receiving RA guard protection. What is the most likely reason?
Explanation: RA Guard protection is applied per interface based on trust configuration. The exhibit shows the device with MAC aaaa.bbbb.cccc is reachable via Gi0/1/1, but if that interface is not explicitly configured as trusted for RA Guard (e.g., using `ipv6 nd raguard trust`), the switch will not apply RA Guard filtering to RAs received on that port. This allows rogue RA messages from that device to bypass protection, making A the correct answer.
Which TWO configuration steps are required to enable Cisco AMP for Endpoints to use the Threat Grid appliance for file analysis?
Explanation: Option A is correct because the AMP for Endpoints connector policy must be configured to point file submissions to the on-premises Threat Grid appliance, which is done by selecting the private Threat Grid appliance as the analysis destination in the policy's file analysis settings. Option C is correct because the on-premises Threat Grid appliance must be registered with the AMP cloud as a private analysis provider, which establishes the trust and routing so the AMP cloud knows to send files to that appliance for analysis. Option B is incorrect because SSL decryption is unrelated to file submission to Threat Grid and is not a required configuration step. Option D is incorrect because the Threat Grid appliance initiates outbound connections to the AMP cloud and does not require inbound internet traffic to function as a private analysis provider. Option E is incorrect because the Threat Grid Connector is not installed on endpoints; integration is handled through the AMP connector policy and cloud registration.
Which THREE of the following are valid methods to deploy Cisco AMP for Endpoints Connector on Windows endpoints?
Explanation: Group Policy Software Installation (MSI) is a valid deployment method for Cisco AMP for Endpoints Connector on Windows endpoints because it allows administrators to distribute the AMP connector MSI package via Active Directory Group Policy Objects (GPOs). This method leverages Windows Installer technology for silent, automated installation across domain-joined machines, ensuring consistent deployment without user interaction.
Which TWO indicators of compromise (IOCs) can Cisco AMP for Endpoints detect and alert on?
Explanation: Cisco AMP for Endpoints uses advanced endpoint detection capabilities, including behavioral analysis and machine learning, to detect fileless attack techniques such as PowerShell injection. These techniques do not rely on traditional file-based signatures, but AMP monitors process execution, script activity, and memory patterns to identify malicious behavior in real time.
Refer to the exhibit. An engineer notices that a malicious file disguised as 'app.exe' in the FinanceApp folder (SHA-256 unknown to AMP) was blocked. However, another unknown executable in the same folder was also blocked, causing a false positive. What should the engineer change in the policy to allow only the legitimate 'app.exe' while still blocking unknown executables?
Explanation: The current policy uses a wildcard file exclusion for the entire FinanceApp folder, which causes the AMP engine to skip scanning all files within that folder, including unknown executables. By changing the exclusion to the exact full path of the legitimate 'app.exe', only that specific file is excluded from scanning, while other unknown executables in the folder remain subject to the 'block' action for unknown files. This allows the known good file to execute without being blocked, while still blocking other unknown files that may be malicious.
+15 more scenario questions available
Practice all Hard Difficulty QuestionsThese are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam. These appear throughout the 350-701 and require you to apply your knowledge, not just recall facts.
Cisco doesn't publish an exact breakdown, but scenario-based questions (especially exhibit and command-output formats) make up a significant portion of the 350-701. Practicing each scenario type ensures you're ready for any format.
Yes. Courseiva provides free 350-701 scenario practice across all official exam domains. The platform includes scenario-based questions, command-output interpretation, topic-based practice, mock exams, and readiness tracking — no account required.
Launch a full Hard Difficulty Questions session with instant scoring and detailed explanations.
Start Scenario Practice →