Courseiva
Question 146 of 978
Endpoint Protection and DetectionmediumMultiple ChoiceObjective-mapped

350-701 Endpoint Protection and Detection Practice Question

An organization is deploying Cisco Secure Endpoint (AMP) in a high-security environment where endpoints are air-gapped from the internet. The security team needs to maintain up-to-date threat intelligence without direct cloud access. They have a dedicated local server that can download feeds from the AMP cloud once and distribute to endpoints. The server runs the AMP Private Cloud software. However, after installation, endpoints are not receiving updates. The team verifies that the Private Cloud server can reach the AMP cloud via a managed proxy. The endpoints can communicate with the Private Cloud server on TCP 443. What is the most likely cause of the update failure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The Private Cloud appliance has not been registered and licensed in the AMP console.

The Private Cloud must be registered and licensed with Cisco to receive updates. Without registration, it cannot download threat intelligence. Option A (proxy misconfiguration) is possible but the team verified the proxy works. Option C (endpoint certificate issue) is less likely; endpoints authenticate via policy. Option D (Private Cloud out of disk space) would log errors, but not the primary cause if the server is newly set up.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The proxy is not properly configured to allow HTTPS from the Private Cloud to the AMP cloud.

    Why it's wrong here

    The team already verified the proxy connection.

  • The Private Cloud appliance has not been registered and licensed in the AMP console.

    Why this is correct

    Registration is required to sync threat intelligence.

  • The endpoints are using an incorrect certificate to authenticate to the Private Cloud.

    Why it's wrong here

    Endpoints authenticate using policy-specified credentials.

  • The Private Cloud server's disk is full, preventing new update downloads.

    Why it's wrong here

    Disk space full would generate alerts, but less likely as initial cause.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 24, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.