350-701 Endpoint Protection and Detection Practice Question
A security analyst is investigating an alert from Cisco Secure Endpoint indicating that an endpoint has been infected with ransomware. The analyst wants to determine the initial infection vector. Which feature of Cisco Secure Endpoint should the analyst use to trace the chain of events leading to the infection?
⚠ Common exam trap
Cisco often tests the distinction between network-level analysis (TETRA, Device Flow Correlation) and endpoint-level forensic investigation (Orbital), leading candidates to confuse traffic analysis with host-based event chain reconstruction.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Orbital Advanced Search
Orbital Advanced Search is the correct feature because it provides deep forensic visibility into endpoint activity, allowing the analyst to perform advanced queries across files, processes, registry keys, and network connections. This enables tracing the chain of events—such as a malicious email attachment, exploit, or drive-by download—that led to the ransomware infection, by correlating timestamps and process parent-child relationships.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Orbital Advanced Search
Why this is correct
Orbital Advanced Search provides retrospective analysis to trace the attack chain.
- ✗
TETRA traffic analysis
Why it's wrong here
TETRA provides real-time network traffic analysis, not historical tracing.
- ✗
Windows Event Viewer integration
Why it's wrong here
Windows Event Viewer is not integrated into AMP.
- ✗
Device Flow Correlation
Why it's wrong here
This is not a feature of Cisco Secure Endpoint.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 350-701 question from scratch — 978 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.