Courseiva
hardMultiple ChoiceObjective-mapped

350-701 Practice Question: Refer to the exhibit

Exhibit

Refer to the exhibit.

Malware Event: 2024-03-15 10:23:45 UTC
File Name: invoice_2024.exe
SHA256: a1b2c3d4e5f6...
Score: 100 (Cisco AMP)
Disposition: Malicious

Syslog from ESA:
Mar 15 10:23:45 mail.esa.cisco.com CEF:0|Cisco|Email Security Appliance|13.0|ESA|EMAIL_MALWARE|5|act=blocked dvc=10.1.1.10 dst=192.168.1.100 msg=Attachment blocked: invoice_2024.exe cn1Label=AMP Verdict cn1=100 cs4Label=File SHA256 cs4=a1b2c3d4e5f6...

Refer to the exhibit. An administrator sees that the file invoice_2024.exe was blocked by both Cisco AMP and ESA. However, a user claims the attachment was delivered. What is the most likely cause?

⚠ Common exam trap

Cisco often tests the distinction between 'Deliver then alert' and 'Block' or 'Deliver and alert' modes in ESA AMP integration, where candidates mistakenly assume that a block in AMP logs means the file was never delivered, but the 'Deliver then alert' policy allows delivery before the block verdict is received.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The ESA was configured to 'Deliver then alert' for malware detected by AMP.

When Cisco ESA is configured with 'Deliver then alert' for malware detected by AMP, the email is delivered to the user before the AMP file reputation analysis completes. The ESA sends the file to AMP for analysis, but if the policy is set to deliver first and alert later, the user receives the attachment even if AMP later determines it is malicious. This explains why the administrator sees the block in both AMP and ESA logs, yet the user claims delivery.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The ESA was not configured to use AMP for file reputation.

    Why it's wrong here

    The exhibit shows AMP verdict, so it was configured.

  • The ESA was configured to 'Deliver then alert' for malware detected by AMP.

    Why this is correct

    In 'Deliver then alert' mode, the email is delivered and an alert is sent, explaining why the user received it.

  • The AMP file reputation check was not performed due to an ACL misconfiguration.

    Why it's wrong here

    The exhibit shows AMP verdict 100, so the check was performed.

  • The file was whitelisted in the AMP policy.

    Why it's wrong here

    A score of 100 indicates malicious, not whitelisted.

About these practice questions

Courseiva writes every 350-701 question from scratch — 978 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.