CCNP Security 300-710 SNCF Practice Test 24

CCNP Security 300-710 SNCF Practice Test 24 (Hard) - Intrusion and Malware Event Analysis

CISCO CCNP Security Exam Logo

1 / 10

Which FMC event type records details about a specific traffic match against an intrusion rule signature, including the rule that fired and the classification of the detected activity?

2 / 10

Which FMC event type records the disposition (such as clean, malware, or unknown) assigned to a file observed traversing the network, based on file policy inspection?

3 / 10

Which intrusion event field would an analyst review to assess the potential severity or business impact of a detected signature match?

4 / 10

Which capability allows FMC to assess the likely relevance of an intrusion event to a specific host, by correlating the event against known host attributes such as operating system and installed applications?

5 / 10

Which malware event disposition would indicate that a file was analyzed and found to contain no known malicious characteristics, based on the configured detection methods?

6 / 10

Which follow-up action would be most appropriate after an analyst identifies a high-impact intrusion event that correlates strongly with a host's known vulnerable software version?

7 / 10

Which malware event workflow capability allows an analyst to retrieve a copy of a suspicious file for further offline or sandbox analysis, if file storage/capture was enabled in the file policy?

8 / 10

Which retrospective malware capability would alert an analyst if a file previously judged clean is later reclassified as malware based on updated threat intelligence?

9 / 10

Which combination of intrusion and malware event analysis practices would help a SOC analyst efficiently prioritize investigation effort across a high volume of daily events?

10 / 10

Which reporting practice would help demonstrate the overall effectiveness of intrusion and malware defenses to organizational leadership over a quarterly period?

Your score is

The average score is 0%

0%