Skip to content

500-275 Practice Questions

Prepare for 500-275 with more than an answer.

228 questions in the full set17 sample questionsUpdated Jan 23, 2026
Exam fee
$300 USD
Level
Specialist
Valid for
2 years
Domains covered on the exam 9
  1. Cisco Advanced Malware Protection Overview and Architecture20%
  2. Outbreak Control Menu Items9%
  3. Endpoint Policies9%
  4. Groups and Deployment12%
  5. Analysis and Reporting18%
  6. Private Cloud10%
  7. Accounts6%
  8. Cisco AMP Connector6%
  9. Console Interface10%
  1. 1

    CASE STUDY: TechGlobal Inc.

    TechGlobal Inc. is a software development firm migrating to Cisco AMP. They have a mix of Windows 10 workstations and Linux build servers. The development team compiles custom executables frequently.

    Recently, developers reported that their proprietary build tools are being flagged and quarantined by AMP, halting production. The security team needs to resolve this while maintaining security posture.

    Which type of exclusion should the administrator configure to prevent the build tools from being scanned while still scanning the files they create?

    Show answer details

    Correct answer: B

    A Process Exclusion allows the specified process (the build tool) to run without being monitored by the connector, but files created or modified by other processes are still scanned. This prevents the tool itself from being flagged while maintaining security on the output if needed, or more specifically, prevents performance impact on the tool's operations.

  2. 2

    When configuring a policy for a Virtual Desktop Infrastructure (VDI) environment with non-persistent desktops, which specific connector setting helps prevent the creation of duplicate connector records in the console every time a VDI instance spins up?

    Show answer details

    Correct answer: B

    Identity Persistence allows the AMP connector to recognize that it is running on a non-persistent VDI endpoint. It uses MAC addresses or hostnames to map the endpoint to an existing connector record rather than creating a new GUID for every session.

  3. 3

    What is the primary function of the 'Triage' policy mode in Cisco AMP for Endpoints?

    Show answer details

    Correct answer: B

    Triage mode is designed for endpoints that are already compromised. It enables the connector to report on infection activity and artifacts (like file drops) without interfering or blocking, allowing security teams to observe the malware's behavior for analysis.

  4. 4

    An administrator is preparing to install the AMP connector on a Windows server. Which command-line switch should be used with the installer to hide the user interface during installation?

    Show answer details

    Correct answer: B

    The /silent switch performs the installation without displaying the installation wizard or progress bar to the user.

  5. 5

    When planning a deployment of Cisco AMP Connectors, why is it critical to organize endpoints into Groups within the console?

    Show answer details

    Correct answer: C

    In the FireAMP/AMP for Endpoints architecture, Policies are applied to Groups. Endpoints are placed into Groups, and they inherit the Policy assigned to that Group. This is the primary mechanism for applying different configurations (e.g., Audit vs. Protect) to different sets of computers.

  6. 6

    Incident responders use which policy mode for outbreak control? A.AuditB.ProtectC.TriageD.Emergency

    Show answer details

    Correct answer: C

  7. 7

    When you are viewing information about a computer, what is displayed? A.the type of antivirus software that is installedB.the internal IP addressC.when the operating system was installedD.the console settings

    Show answer details

    Correct answer: B

  8. 8

    How can customers feed new intelligence such as files and hashes to FireAMP? A.by uploading it to the FTP serverB.from the connectorC.through the management consoleD.by sending it via email

    Show answer details

    Correct answer: C

Create an account to continue.