Courseiva
Endpoint Protection and DetectionmediumMultiple ChoiceObjective-mapped

350-701 Endpoint Protection and Detection Practice Question

A security engineer is deploying Cisco AMP for Endpoints to protect against malware. The company wants to block all executables from running in the Downloads folder except those signed by a specific trusted publisher. Which policy configuration should the engineer use?

⚠ Common exam trap

Candidates often confuse malware protection policies (which rely on reputation and analytics) with Application Control rules (which enforce explicit allow/block based on path and publisher), leading them to select the default malware protection option despite it not supporting folder-specific blocking based on publisher trust.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create an Application Control rule to block all executables in the Downloads folder and add an exception for the trusted publisher.

Cisco AMP for Endpoints uses Application Control rules to allow or block executables based on file path and publisher certificate. By creating a rule that blocks all executables in the Downloads folder and adding an exception for executables signed by the trusted publisher, the engineer achieves the exact requirement—only trusted signed executables can run from that folder.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use the default malware protection policy, which automatically blocks untrusted executables in Downloads.

    Why it's wrong here

    Default policy blocks known malware but not all untrusted executables by path.

  • Create an Application Control rule to block all executables in the Downloads folder and add an exception for the trusted publisher.

    Why this is correct

    Application Control allows blocking by path and creating exceptions based on publisher certificate.

  • Configure an Exclusion for the Downloads folder and then use a Custom Detection for untrusted executables.

    Why it's wrong here

    Exclusions prevent scanning, not execution; they do not block execution.

  • Enable Simple Custom Detections with the SHA-256 hashes of all known executables.

    Why it's wrong here

    Simple Custom Detections block files based on hash, not path or publisher.

About these practice questions

This 350-701 question is part of Courseiva's 978-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.