exam questions

Exam 350-701 All Questions

View all questions & answers for the 350-701 exam

Exam 350-701 topic 1 question 638 discussion

Actual exam question from Cisco's 350-701
Question #: 638
Topic #: 1
[All 350-701 Questions]

Which action adds IOCs to customize detections for a new attack?

  • A. Use the initiate Endpoint 1OC scan feature to gather the IOC information and push it to clients.
  • B. Upload the 10Cs into the Installed Endpoint IOC feature within Cisco Secure Endpoint.
  • C. Add a custom advanced detection to include the 1OCs needed within Cisco Secure Endpoint.
  • D. Modify the base policy within Cisco Secure Endpoint to include simple custom detections.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
madboy2
1 month, 2 weeks ago
Selected Answer: C
Indicators of Compromise (IOCs) are used in cybersecurity to detect and respond to potential threats by identifying malicious behaviors, files, or network activity. In Cisco Secure Endpoint, IOCs can be manually added to improve threat detection for new or evolving attacks. 🔹 Why is Option C Correct? Cisco Secure Endpoint allows administrators to define custom advanced detections based on specific IOCs (e.g., file hashes, IPs, domains, behaviors). This customization enhances malware detection and response by including new threats that may not yet be covered by Cisco’s global intelligence.
upvoted 2 times
...
klu16
8 months, 2 weeks ago
Selected Answer: B
Based on: https://www.cisco.com/c/en/us/support/docs/security/advanced-malware-protection-endpoints/118899-technote-malwareprotection-00.html#anc5 I think B is correct.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago