CCNP Security 350-701 SCOR Practice Test 24

CCNP Security 350-701 SCOR Practice Test 24 (Hard) - Endpoint Detection and Response (EDR) Concepts

CISCO CCNP Security Exam Logo

1 / 10

Which capability distinguishes an Endpoint Detection and Response (EDR) solution from traditional signature-only antivirus software?

2 / 10

Which EDR concept refers to the detailed stream of endpoint activity data (process creation, file access, registry changes, network connections) continuously collected for later analysis?

3 / 10

Which EDR workflow step involves an analyst reviewing collected telemetry and contextual data to determine whether a flagged event represents an actual security incident or a benign false positive?

4 / 10

Which EDR response action would allow an analyst to terminate a malicious process running on an endpoint directly from the management console, without needing physical access to the device?

5 / 10

Which EDR concept describes a low-confidence, ambiguous signal that on its own may not indicate compromise, but combined with other similar signals across an investigation may reveal malicious intent?

6 / 10

Which EDR capability allows security teams to proactively search across the endpoint fleet for subtle signs of an intrusion that automated detection rules did not already flag?

7 / 10

Which metric would a SOC team track to evaluate how quickly analysts identify a genuine security incident after the first related telemetry event occurred?

8 / 10

Which EDR integration allows automatically enriching an endpoint alert with external threat intelligence context, such as whether a related file hash or IP has been seen in other known campaigns?

9 / 10

Which EDR/SOAR concept describes automatically executing a predefined sequence of response actions (such as isolate host, kill process, notify analyst) when a high-confidence detection occurs, without requiring manual step-by-step execution?

10 / 10

Which combination of EDR capabilities together provides the most effective detection-through-response lifecycle for a SOC handling a suspected endpoint compromise?

Your score is

The average score is 0%

0%