Courseiva
Endpoint Protection and DetectionmediumMultiple ChoiceObjective-mapped

350-701 Endpoint Protection and Detection Practice Question

A company uses Cisco AMP for Endpoints and also deploys Cisco Firepower Next-Generation Firewall (NGFW) with AMP integration. The security team wants to see endpoint detections in the Firepower Management Center (FMC). What must be configured to enable this integration?

⚠ Common exam trap

Cisco often tests the misconception that on-premises components or Syslog are required for AMP-FMC integration, when in fact the integration relies solely on cloud-based API credentials and does not involve Syslog or an on-premises AMP console.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Enable the AMP integration in the FMC and ensure the AMP cloud account is configured with the correct API credentials.

Cisco AMP for Endpoints integrates with Firepower Management Center (FMC) via the AMP cloud API. To enable this, the FMC must have the AMP integration enabled and be configured with the correct API credentials (Client ID and API Key) from the AMP cloud console. This allows the FMC to pull endpoint detection events directly from the AMP cloud, correlating them with network-based detections from the Firepower NGFW.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable the AMP integration in the FMC and ensure the AMP cloud account is configured with the correct API credentials.

    Why this is correct

    The integration uses API calls between FMC and AMP cloud to exchange threat intelligence.

  • Configure the AMP connectors to send Syslog events to the FMC.

    Why it's wrong here

    Syslog is not the standard integration method; AMP cloud API is used.

  • Deploy an on-premises AMP console to forward events to FMC.

    Why it's wrong here

    On-premises console is not required; cloud integration is direct.

  • Configure the Firepower NGFW to be the default gateway for the endpoints.

    Why it's wrong here

    Gateway configuration is irrelevant to AMP integration.

About these practice questions

One of 978 original 350-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.