Cisco CCNP Security SCOR (350-701) · Domain 5 · 10% of exam

Endpoint Protection and Detection

Drill 15 practice questions focused entirely on Endpoint Protection and Detection for the Cisco 350-701 exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.

Verified answer15 questions
Question 1 of 15

A security architect at a mid-sized firm is presenting a proposal to the board after several workstations were compromised through a publicly known exploit that had a vendor fix available for three months. The board asks why a formal endpoint patching strategy should be prioritized over simply relying on the company's existing Cisco Secure Endpoint deployment. Which justification BEST explains the primary value a structured patching strategy adds beyond antimalware/EDR tooling?

Reviewed for accuracy · Report an issue
Question 2 of 15

A security architect is evaluating endpoint tools for an enterprise. The team already blocks known malware effectively but repeatedly struggles to answer questions like 'What did this file do after execution?', 'Which other hosts were affected?', and 'Can we roll back or contain a compromised machine from a central console after the fact?'. Which class of solution should the architect prioritize to address these specific gaps?

Reviewed for accuracy · Report an issue
Question 3 of 15

A security manager at a mid-sized firm discovers that several employees are accessing corporate email and cloud file shares from personal smartphones that IT has no record of. Leadership wants a solution that both maintains an authoritative inventory of every device touching corporate resources and can enforce configuration requirements (screen lock, encryption, remote wipe) on those devices before granting access. Which solution category best meets this requirement?

Reviewed for accuracy · Report an issue
Question 4 of 15

A financial services company has issued corporate laptops with Cisco Secure Endpoint installed and a strict patching policy. During a security review, the CISO asks why the organization still needs to invest in endpoint-based security controls when the corporate network already has next-generation firewalls, IPS, and a secure web gateway inspecting all traffic. Which justification best supports the continued need for endpoint-based security?

Reviewed for accuracy · Report an issue
Question 5 of 15

A financial services company recently suffered an incident where an attacker obtained employee credentials via a phishing site and then used a real-time relay to intercept the one-time passcodes users typed in, successfully logging into the VPN. Leadership wants the security team to strengthen the MFA strategy so that a stolen password AND an intercepted code cannot be replayed by an attacker. Which MFA approach best meets this requirement?

Reviewed for accuracy · Report an issue
Question 6 of 15

A company uses Cisco ISE with posture assessment to control network access for corporate laptops. Security policy requires that any endpoint missing the latest antivirus definitions be given limited access to a remediation server to download updates, rather than full network access, until it becomes compliant. Which ISE posture concept enforces this behavior?

Reviewed for accuracy · Report an issue
Question 7 of 15

A security engineer is deploying Cisco Secure Endpoint connectors to 3,000 Windows workstations. Leadership is concerned that aggressive blocking could disrupt line-of-business applications during the initial rollout. The engineer needs the connectors to fully monitor file activity, generate detections and events, and populate device trajectory, but NOT quarantine or block any files while the team validates behavior against legitimate applications. Which connector engine/policy configuration meets these requirements during the pilot phase?

Reviewed for accuracy · Report an issue
Question 8 of 15

A security analyst at a manufacturing firm confirms that a specific host on the network is running a malicious process that is beaconing to a command-and-control server. Cisco Secure Endpoint connectors are deployed on all endpoints. The analyst needs to immediately stop the infected endpoint from communicating with any other internal or external systems while the incident response team investigates, but must keep the connector installed and reporting. Which Secure Endpoint outbreak control feature should the analyst use?

Reviewed for accuracy · Report an issue
Question 9 of 15

An incident responder using Cisco Secure Endpoint sees that a suspicious executable was detected on a finance workstation. The responder needs to determine exactly which parent process launched the file, what files it created afterward, and the sequence of activity on that single host to identify the root cause of the compromise. Which Secure Endpoint feature should the responder use?

Reviewed for accuracy · Report an issue
Question 10 of 15

A financial services company has deployed Cisco Secure Endpoint on all Windows workstations. During a recent incident, attackers used a weaponized document that injected malicious code into a legitimate running process (a technique that leaves no file on disk) to execute a fileless attack. The security team wants to enable the Secure Endpoint capability that specifically defends against this class of in-memory attack without relying on file hash lookups or signature matching. Which Secure Endpoint engine should they enable?

Reviewed for accuracy · Report an issue
Question 11 of 15

A security analyst deployed Cisco Secure Endpoint across the organization. After a new custom-built internal application was rolled out, the Secure Endpoint connectors on several workstations quarantined the application's main executable, disrupting business operations. Investigation confirms the file is safe and the detection was a false positive. The analyst must restore the file on the affected endpoints and prevent Secure Endpoint from quarantining it again in the future. Which action set accomplishes both goals?

Reviewed for accuracy · Report an issue
Question 12 of 15

A security analyst deploys Cisco Secure Endpoint connectors across the enterprise. During an incident, a file that was previously allowed on hundreds of endpoints is later confirmed to be malicious by Cisco Talos and reclassified in the cloud. The analyst wants the connectors to automatically quarantine that file wherever it exists—including on endpoints that executed it days ago—without pushing a new custom detection or scanning every disk again. Which Secure Endpoint capability delivers this outcome?

Reviewed for accuracy · Report an issue
Question 13 of 15

A security analyst at a financial firm has identified that several endpoints are communicating with a newly discovered command-and-control server at IP address 203.0.113.45. The analyst wants to immediately stop all Cisco Secure Endpoint-protected machines from establishing outbound connections to this specific IP, even before the threat intelligence feeds are updated globally. Which outbreak control feature should the analyst use to accomplish this?

Reviewed for accuracy · Report an issue
Question 14 of 15

During an active incident, threat intelligence confirms that a legitimately signed but abused remote-access tool (a portable .exe running from user profile directories) is being used by attackers for lateral movement across Windows endpoints managed by Cisco Secure Endpoint. The security team must immediately stop this specific executable from launching on all endpoints, but antivirus engines do not flag it as malicious because it is a valid application. Which outbreak control mechanism should the team use?

Reviewed for accuracy · Report an issue
Question 15 of 15

A financial services SOC has confirmed a malicious executable circulating internally. VirusTotal shows the file is not yet detected by most engines, but the SOC has the file's SHA-256 hash. They need Cisco Secure Endpoint to immediately block and quarantine only this exact file on all managed endpoints, without affecting any other files. Which outbreak control mechanism should they configure?

Reviewed for accuracy · Report an issue

More 350-701 practice

Keep going with the other Cisco CCNP Security SCOR (350-701) domains, or take a full timed mock exam.

← Back to 350-701 overview