20+ practice questions focused on Endpoint Protection and Detection — one of the most tested topics on the Cisco SCOR / CCNP Security Core 350-701 exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Endpoint Protection and Detection PracticeA multinational company plans to deploy Cisco AMP for Endpoints across 10,000 endpoints in geographically diverse offices. The security team is concerned about WAN bandwidth usage when endpoints communicate with the AMP cloud. Which design approach best minimizes cloud communication traffic while maintaining effective protection?
Explanation: Deploying an AMP Private Cloud appliance on-site allows endpoints to perform local reputation queries, keeping traffic within the LAN and minimizing WAN bandwidth usage. Option A is wrong because disabling real-time file scanning and relying solely on scheduled scans leaves endpoints vulnerable between scans, significantly reducing protection. Option B is wrong because reducing the frequency of file reputation lookups by setting a longer cache time can delay detection of new threats, compromising security. Option C is wrong because a forward proxy caches AMP cloud responses but still requires WAN queries for cache misses and introduces additional latency; it does not reduce cloud communication traffic as effectively as a local private cloud.
Based on the exhibit, what is the most likely reason that traffic matching the AMP_block access-list is not being blocked?
Explanation: For an access-list to affect traffic on a Cisco Firepower Threat Defense (FTD) device, it must be referenced within a policy-map (e.g., using the `class-map` and `policy-map` configuration). The AMP_block access-list is defined but not referenced in any policy-map, so it is not applied to traffic. Option A is incorrect because the remark command syntax does not affect blocking; remarks are just comments. Option B is incorrect because the problem is not that the policy-map lacks a pass or block action; rather, the access-list itself is not referenced at all in any policy-map. Option D is incorrect because on FTD, access-lists are not applied directly to interfaces; they are used within policy-maps which are then applied to interfaces. Therefore, the lack of interface application is not the root cause.
A security administrator notices that several endpoints in the finance department are exhibiting unusual network behavior, including connections to known malicious IP addresses. The administrator has deployed Cisco Secure Endpoint (formerly AMP for Endpoints) with TETRA and has enabled the built-in firewall. What is the best course of action to quickly identify the root cause and contain the threat?
Explanation: Cisco Secure Endpoint with TETRA provides real-time traffic analysis and endpoint isolation capabilities directly from the console. The TETRA engine inspects network flows using behavioral analysis and machine learning, and the administrator can immediately isolate affected endpoints to prevent lateral movement while reviewing the root cause.
An organization wants to prevent malware from executing on endpoints by using a file reputation service. Which Cisco technology provides cloud-based file reputation and analysis for endpoint protection?
Explanation: Cisco Secure Endpoint (formerly AMP for Endpoints) is the correct answer because it provides cloud-based file reputation and analysis through its Advanced Malware Protection (AMP) cloud. This service uses global threat intelligence and machine learning to analyze file behavior, assign reputation scores, and block or quarantine malicious files on endpoints in real time.
A security engineer is troubleshooting an issue where a known malicious file (SHA-256: 3a7c...f9e) is not being detected by Cisco Secure Endpoint on a Windows 10 endpoint. The file was downloaded from the internet. The policy has the 'File Reputation' setting set to 'Use cloud lookup', and the 'Exploit Prevention' module is enabled. The endpoint is connected to the internet and can reach the AMP cloud. What is the most likely reason for the missed detection?
Explanation: Cisco Secure Endpoint's 'File Reputation' with 'Use cloud lookup' requires the endpoint to be online at the moment the file is written to disk. If the endpoint was offline during that critical window, the connector cannot perform the SHA-256 cloud lookup against the AMP cloud, and the file is not evaluated for maliciousness. The file remains undetected until a subsequent scan or event triggers a new lookup, which may not happen automatically.
+15 more Endpoint Protection and Detection questions available
Practice all Endpoint Protection and Detection questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Endpoint Protection and Detection. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Endpoint Protection and Detection questions on the 350-701 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Endpoint Protection and Detection is tested as part of the Cisco SCOR / CCNP Security Core 350-701 blueprint. Practicing with targeted Endpoint Protection and Detection questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free 350-701 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Endpoint Protection and Detection is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Endpoint Protection and Detection practice session with instant scoring and detailed explanations.
Start Endpoint Protection and Detection Practice →