Endpoint Protection and Detection for Implementing and Operating Cisco Security Core Technologies (SCOR 350-701)

This page covers the Endpoint Protection and Detection domain of the Implementing and Operating Cisco Security Core Technologies (SCOR 350-701) certification. Master Cybersecurity offers 13 practice questions in this domain, drawn from the same content we use across our timed exam simulations. Below are five sample questions with full answer explanations.

Sample Practice Questions

  1. Question 1

    Refer to the exhibit. What does the API do when connected to a Cisco security appliance?
    1. A. create an SNMP pull mechanism for managing AMP
    2. B. gather network telemetry information from AMP for endpoints
    3. C. get the process and PID information from the computers in the network
    4. D. gather the network interface information about the computers AMP sees
    Explanation

    The correct answer is: D. gather the network interface information about the computers AMP sees.

    Every host entry the Cisco Secure Endpoint, formerly AMP for Endpoints, cloud API returns carries a network_addresses element listing the MAC and IP addresses bound to that machine's adapters, so a script that walks the computers collection and prints those fields is effectively building an interface inventory of each endpoint the connectors report. SNMP is not involved: the platform is administered through an authenticated REST API over HTTPS, and calling it creates no polling mechanism. Running process and PID detail is not exposed by the inventory resource either - that level of execution data appears in device trajectory and event records for a specific host, which reconstruct what executed and in what order. Network telemetry in the flow-record sense comes from the Network Visibility Module of Cisco Secure Client rather than from endpoint inventory queries, so interface addressing is what this request actually yields.

  2. Question 2

    Refer to the exhibit. What will happen when this Python script is run?
    1. A. The list of computers, policies, and connector statuses will be received from Cisco AMP.
    2. B. The list of computers and their current vulnerabilities will be received from Cisco AMP.
    3. C. The compromised computers and malware trajectories will be received from Cisco AMP.
    4. D. The compromised computers and what compromised them will be received from Cisco AMP.
    Explanation

    The correct answer is: A. The list of computers, policies, and connector statuses will be received from Cisco AMP..

    The script authenticates to the Cisco Secure Endpoint, formerly AMP for Endpoints, cloud API with a client ID and API key and requests the computers collection, so what comes back is the connector inventory: every registered host with its hostname, operating system, connector GUID and version, the policy assigned to it, and its current connector status, including whether it has checked in recently. Vulnerability data is not part of that response; it is returned by the dedicated vulnerabilities resource, which correlates installed application versions against known CVEs. Compromise and malware trajectory detail also comes from different resources - the events and trajectory endpoints - which return the ordered sequence of file and process activity behind a detection on a specific host. Because this request targets only the inventory resource, the output is a roster of endpoints with their policy and connector health, not detection or exposure findings.

  3. Question 3

    Which Cisco platform processes behavior baselines, monitors for deviations, and reviews for malicious processes in data center traffic and servers while performing software vulnerability detection?
    1. A. Cisco Tetration
    2. B. Cisco ISE
    3. C. Cisco AnyConnect
    4. D. Cisco AMP for Network
    Explanation

    The correct answer is: A. Cisco Tetration.

    The platform named Tetration, now Cisco Secure Workload, is purpose-built for the data center: sensors on servers and workloads report process, flow, and package inventory to a central engine that learns a behavior baseline for each application tier, alerts on deviations from it, flags malicious or unexpected processes, and inventories installed software to surface known CVEs, all of which feeds the policy used for micro-segmentation. Cisco ISE is an identity and access control service that authenticates and profiles users and devices and applies network authorization; it does not baseline workload behavior. AnyConnect, now Cisco Secure Client, is the endpoint agent framework that supplies VPN, posture, and telemetry modules to user machines, so it is a client rather than a data center analytics engine. The network-based malware option inspects files as they traverse Cisco Secure Firewall sensors and assigns dispositions to them, which is file-level detection in transit, not server behavior baselining with vulnerability detection.

  4. Question 4

    What are two list types within Cisco AMP for Endpoints Outbreak Control? (Choose two.)
    1. A. blocked ports
    2. B. simple custom detections
    3. C. command and control
    4. D. allowed applications
    5. E. URL
    Explanation

    The correct answers are: B. simple custom detections, D. allowed applications.

    Outbreak Control in Cisco Secure Endpoint, formerly AMP for Endpoints, is a set of administrator-maintained lists, and simple custom detections is one of them: SHA-256 values the connector treats as malicious and quarantines on sight, the fastest way to stop a specific file during an incident. Allowed applications is another, naming the SHA-256 of software that must be permitted to run even when reputation or an engine would otherwise flag it, which is how false positives on business-critical binaries are suppressed. The remaining Outbreak Control lists cover blocked applications, advanced custom detections built from ClamAV signatures, IP block and allow lists, and Endpoint IOC scanning. Blocked ports are a host or network firewall construct, not an Outbreak Control list. Command and control is a phase of attacker behavior that IP block lists help disrupt, rather than a list type. URL filtering belongs to web security products such as Cisco Umbrella and Secure Web Appliance.

  5. Question 5

    What is the primary difference between an Endpoint Protection Platform and an Endpoint Detection and Response?
    1. A. EPP focuses on prevention, and EDR focuses on advanced threats that evade perimeter defenses.
    2. B. EDR focuses on prevention, and EPP focuses on advanced threats that evade perimeter defenses.
    3. C. EPP focuses on network security, and EDR focuses on device security.
    4. D. EDR focuses on network security, and EPP focuses on device security.
    Explanation

    The correct answer is: A. EPP focuses on prevention, and EDR focuses on advanced threats that evade perimeter defenses..

    An Endpoint Protection Platform is a preventive control set - signature antivirus, reputation and hash blocking, application allow-listing, host firewall, device control - all aimed at stopping known bad code before it ever executes. Endpoint Detection and Response assumes some threats will slip past that first line, so it continuously records process, file, registry, and network telemetry from every host and gives an analyst the means to hunt, scope, and remediate, through features such as file and device trajectory, retrospective verdicts, and host isolation in Cisco Secure Endpoint, formerly AMP for Endpoints. Swapping the two roles inverts the model, because EDR is explicitly the investigate-and-respond layer rather than the blocking layer. The pairings that split the two along network-versus-device lines also miss the mark: both technologies live on the endpoint itself and neither is a network security product, so the real distinction is prevention versus detection and response.

Other Implementing and Operating Cisco Security Core Technologies (SCOR 350-701) domains

Practice all 13 Endpoint Protection and Detection questions · Browse Implementing and Operating Cisco Security Core Technologies (SCOR 350-701)