500-275 Sample Questions & Answers
AMP's technology and architecture get the most attention, with smaller sections on malware analysis and IOC dashboards, deployment planning, endpoint and file policies, outbreak-control whitelisting, private-cloud setup, and the connector itself.
Launch the full 500-275 simulator →Showing 8 of 17 free samples.
- Question 1Advanced
Cisco Advanced Malware Protection Overview and Architecture · AMP Architecture
A multinational financial institution is designing a Cisco AMP deployment. They require a solution where endpoints verify file disposition with a local appliance to minimize external traffic, but the appliance must maintain real-time synchronization with global threat intelligence without allowing direct inbound connections from the internet. Which architecture component and configuration best satisfies this requirement?
Show answer & explanation
Correct answer: B
The Private Cloud in Proxy Mode allows the appliance to act as the local authority for endpoints while maintaining an outbound connection to the Cisco public cloud for real-time disposition updates. This satisfies the requirement for local lookup traffic minimization and real-time synchronization without requiring direct inbound internet access.
- Question 2Intermediate
Cisco Advanced Malware Protection Overview and Architecture · AMP Technology and Features
While analyzing the effectiveness of the Spero engine on Windows endpoints, an engineer notices that machine learning analysis is not occurring for certain files. What is the technical requirement regarding the file structure for the Spero engine to function correctly?
Show answer & explanation
Correct answer: B
The Spero engine relies on machine learning analysis of the structural attributes of Portable Executable (PE) files. If the file is not a PE file (e.g., a PDF or script), Spero cannot generate the necessary feature set for analysis.
- Question 3Intermediate
Cisco Advanced Malware Protection Overview and Architecture · AMP Technology and Features
A security analyst is investigating a retrospective event. A file initially deemed 'Unknown' and allowed to run was later identified as malicious by the AMP Cloud. Which specific mechanism allows Cisco AMP to retroactively alert the administrator and provide the trajectory of this file?
Show answer & explanation
Correct answer: D
Cisco AMP tracks file activity over time using a unique identifier (SHA-256). When the global intelligence network updates a file's disposition from Unknown to Malicious based on big data analytics, the cloud pushes a retrospective alert to all endpoints that have seen that file, enabling the administrator to view the full trajectory.
- Question 4Advanced
Cisco Advanced Malware Protection Overview and Architecture · Endpoint Communication
Refer to the diagram. An organization has deployed Cisco AMP connectors. Based on the decision flow shown, what happens when the AMP Connector encounters a file that is NOT in its local cache?
Show answer & explanation
Correct answer: D
When a file is accessed and not found in the local cache, the connector calculates the SHA-256 hash and queries the AMP Cloud (or Private Cloud console) for the file's disposition.
flowchart TD Start([File Access]) --> Cache{In Local Cache?} Cache -->|Yes| Action[Apply Cached Disposition] Cache -->|No| Hash[Calculate SHA-256] Hash --> Cloud{Lookup in Cloud} Cloud -->|Malicious| Block[Block & Alert] Cloud -->|Unknown| Analyze[Send for Analysis] Cloud -->|Clean| Allow[Allow Execution] - Question 5IntermediateSelect 2
Cisco Advanced Malware Protection Overview and Architecture · AMP Technology and Features
Which TWO engine components are primarily responsible for offline protection when the endpoint cannot communicate with the Cisco AMP Cloud? (Select TWO)
Show answer & explanation
Correct answers: B, C
Tetra is the full-signature offline antivirus engine included in the AMP connector. It provides protection when the cloud is unreachable.
Exploit Prevention protects against memory injection attacks and exploits in unpatched software. It functions locally on the endpoint without needing cloud connectivity.
- Question 6Beginner
Outbreak Control Menu Items · Custom Detections
During a malware outbreak, an administrator needs to immediately block a specific file across all endpoints without waiting for a cloud update. Which feature in the Outbreak Control menu should be used?
Show answer & explanation
Correct answer: C
Simple Custom Detections allow an administrator to upload a specific SHA-256 hash or file list to immediately block that file across the organization, bypassing standard cloud disposition.
- Question 7Advanced
Outbreak Control Menu Items · Custom Detections
An organization wants to use Advanced Custom Detections to block variants of a specific malware family. What file format must be uploaded to create an Advanced Custom Detection?
Show answer & explanation
Correct answer: D
Advanced Custom Detections use ClamAV-formatted signature files to detect malware families or specific byte sequences, rather than just simple hash matching.
- Question 8Intermediate
Endpoint Policies · General Policy Settings
A system administrator is deploying FireAMP connectors to a high-performance server farm. To minimize performance impact during the initial baseline scan, which policy mode is recommended for the first 24-48 hours?
Show answer & explanation
Correct answer: A
Audit Mode allows the connector to monitor file activity and generate logs without blocking files. This is ideal for initial deployment to identify potential false positives and tune exclusions before switching to a blocking mode like Protect.
Ready for the real thing?
The full 500-275 simulator has every exam-style question, timed mode, and instant scoring.