Courseiva
Endpoint Protection and DetectionhardMultiple SelectObjective-mapped

350-701 Endpoint Protection and Detection Practice Question

Which THREE of the following are capabilities of Cisco Threat Response (CTR) that integrate with endpoint telemetry for accelerated detection and response?

⚠ Common exam trap

A common mix-up: candidates confuse the capabilities of the endpoint protection agent (e.g., real-time blocking or patching) with the investigative and orchestration functions of Cisco Threat Response, which is a separate cloud service that aggregates telemetry but does not perform active prevention or remediation actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Device Trajectory to visualize the timeline of events on an endpoint

Device Trajectory is a core capability of Cisco Threat Response (CTR) that ingests endpoint telemetry from Cisco Secure Endpoint (formerly AMP for Endpoints). It visualizes a timeline of events—such as process executions, file modifications, and network connections—on a specific endpoint, enabling security analysts to quickly reconstruct the sequence of an attack and accelerate detection and response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Real-time blocking of malicious processes at the endpoint

    Why it's wrong here

    Real-time blocking is performed by the AMP endpoint agent, not CTR.

  • Device Trajectory to visualize the timeline of events on an endpoint

    Why this is correct

    Device Trajectory is a key feature in AMP/CTR for reconstructing events.

  • Centralized search across endpoint, network, and email telemetry

    Why this is correct

    CTR aggregates telemetry from multiple sources for unified search.

  • Automatic deployment of software patches to endpoints

    Why it's wrong here

    Patch management is outside CTR's scope; it focuses on detection and response.

  • Casebook creation to document investigation steps and share with team

    Why this is correct

    CTR allows creating casebooks to track investigations.

About these practice questions

This 350-701 question is part of Courseiva's 978-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.