Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.
Start Scenario PracticeWhich TWO configuration steps are required to enable Cisco AMP for Endpoints to use the Threat Grid appliance for file analysis?
Explanation: Option A is correct because the AMP for Endpoints connector policy must be configured to point file submissions to the on-premises Threat Grid appliance, which is done by selecting the private Threat Grid appliance as the analysis destination in the policy's file analysis settings. Option C is correct because the on-premises Threat Grid appliance must be registered with the AMP cloud as a private analysis provider, which establishes the trust and routing so the AMP cloud knows to send files to that appliance for analysis. Option B is incorrect because SSL decryption is unrelated to file submission to Threat Grid and is not a required configuration step. Option D is incorrect because the Threat Grid appliance initiates outbound connections to the AMP cloud and does not require inbound internet traffic to function as a private analysis provider. Option E is incorrect because the Threat Grid Connector is not installed on endpoints; integration is handled through the AMP connector policy and cloud registration.
Which THREE of the following are valid methods to deploy Cisco AMP for Endpoints Connector on Windows endpoints?
Explanation: Group Policy Software Installation (MSI) is a valid deployment method for Cisco AMP for Endpoints Connector on Windows endpoints because it allows administrators to distribute the AMP connector MSI package via Active Directory Group Policy Objects (GPOs). This method leverages Windows Installer technology for silent, automated installation across domain-joined machines, ensuring consistent deployment without user interaction.
Which TWO indicators of compromise (IOCs) can Cisco AMP for Endpoints detect and alert on?
Explanation: Cisco AMP for Endpoints uses advanced endpoint detection capabilities, including behavioral analysis and machine learning, to detect fileless attack techniques such as PowerShell injection. These techniques do not rely on traditional file-based signatures, but AMP monitors process execution, script activity, and memory patterns to identify malicious behavior in real time.
Which THREE of the following are indicators of compromise (IOCs) that can be detected by Cisco AMP for Endpoints?
Explanation: Cisco AMP for Endpoints uses a combination of signature-based, behavioral, and machine learning analysis to detect threats. Suspicious process execution (B) is a key behavioral IOC, as AMP monitors process trees, spawning patterns, and memory injections to identify malicious activity that may evade signature-based detection.
An organization wants to implement EDR capabilities for endpoints. Which three actions are typically associated with EDR? (Choose three.)
Explanation: EDR (Endpoint Detection and Response) focuses on detecting, investigating, and responding to threats on endpoints, so process isolation (B) is correct because it lets the agent terminate or suspend a malicious process to stop its execution while preserving forensic state. Remote shell investigation (C) is correct because EDR platforms provide remote access to an endpoint's command shell or live-response console so analysts can run commands, inspect memory, and gather artifacts without disrupting the user. File quarantine (E) is correct because EDR can automatically or manually move malicious files to an isolated location, neutralizing the threat while retaining the sample for analysis. Multi-factor authentication (A) is an identity/access control measure, not an endpoint detection-and-response function, and application whitelisting (D) is a preventive application-control technique rather than an EDR detection/investigation/response capability.
+15 more scenario questions available
Practice all Select Two (Multi-Select) QuestionsMulti-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination. These appear throughout the 350-701 and require you to apply your knowledge, not just recall facts.
Cisco doesn't publish an exact breakdown, but scenario-based questions (especially exhibit and command-output formats) make up a significant portion of the 350-701. Practicing each scenario type ensures you're ready for any format.
Yes. Courseiva provides free 350-701 scenario practice across all official exam domains. The platform includes scenario-based questions, command-output interpretation, topic-based practice, mock exams, and readiness tracking — no account required.
Launch a full Select Two (Multi-Select) Questions session with instant scoring and detailed explanations.
Start Scenario Practice →