mediumMultiple ChoiceObjective-mapped
350-701 Practice Question: A multinational corporation uses Cisco AMP for…
A multinational corporation uses Cisco AMP for Endpoints with cloud-based file reputation. The security team notices that a file that was previously determined to be clean (disposition: clean) is now reported as malicious by a threat intelligence feed. However, AMP has not taken any action on endpoints that already executed the file. The administrator confirms that retrospective security is enabled. What should the administrator check first to ensure that the file is remediated on all affected endpoints?
⚠ Common exam trap
Cisco often tests the distinction between 'retrospective security' being enabled (which allows the cloud to send updated dispositions) and the 'Remediate Now' policy setting (which controls whether the endpoint automatically acts on those updates), leading candidates to incorrectly assume that enabling retrospective security alone is sufficient for automatic remediation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check that the policy assigned to the endpoints has the 'Remediate Now' option enabled for files with changed dispositions.
When a file's disposition changes from clean to malicious in the AMP cloud, the 'Remediate Now' policy setting controls whether AMP automatically triggers remediation actions (such as quarantine or deletion) on endpoints that have already executed the file. Even with retrospective security enabled, the administrator must ensure that the policy assigned to the endpoints has this option enabled; otherwise, the cloud will send the updated disposition but the endpoint will not automatically act on it.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Verify that the file is not excluded from scanning due to an anti-virus exclusion list.
Why it's wrong here
Exclusion prevents detection, not remediation.
- ✗
Confirm that the endpoints have internet connectivity to the AMP cloud.
Why it's wrong here
Endpoints likely have connectivity as file was initially analyzed.
- ✓
Check that the policy assigned to the endpoints has the 'Remediate Now' option enabled for files with changed dispositions.
Why this is correct
Requires explicit setting.
- ✗
Ensure that the file is being analyzed by the local AMP engine for accurate detection.
Why it's wrong here
Local analysis not needed for cloud disposition changes.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 350-701 question from scratch — 978 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.