200-901 Question 71
Select 3A network administrator wants to leverage Cisco's security platforms to enhance threat detection and response capabilities across their organization. Which of the following platforms and their associated APIs would best enable the administrator to achieve centralized threat correlation, automated responses, and DNS-layer security?
- A
Cisco XDR for correlating security events and automating responses across multiple security products.
- B
Cisco Firepower for providing DNS-layer security and blocking malicious domains.
- C
Cisco Umbrella for DNS-layer security, content filtering, and preventing access to malicious URLs.
- D
Cisco XDR APIs for introducing automated response workflows by integrating with other security solutions.
- E
Cisco Firepower APIs for creating custom firewall rules and managing intrusion prevention system (IPS) policies.
Show answer and explanation
Correct answers: A, C, D
Explanation
To enhance centralized threat detection and response, Cisco XDR is the ideal platform as it correlates security events across multiple products and automates responses. Cisco Umbrella complements this by providing DNS-layer security, which is important for preventing access to malicious domains. Cisco XDR APIs enable further automation and integration of workflows across diverse security tools, making these three components the most relevant for the scenario described.
- A. Correct.
Cisco XDR (Extended Detection and Response) is specifically designed to correlate threat data across multiple security products, automate responses, and provide centralized visibility.
- B. Incorrect.
Cisco Firepower focuses on intrusion prevention, advanced malware protection, and firewall capabilities, but it does not provide DNS-layer security.
- C. Correct.
Cisco Umbrella provides DNS-layer security, blocks malicious domains, and prevents access to harmful content, enhancing overall security posture.
- D. Correct.
Cisco XDR APIs allow for the integration of security workflows and automation of responses, making it easier to handle threats across a diverse security landscape.
- E. Incorrect.
Cisco Firepower APIs are useful for managing firewall rules and intrusion prevention policies but do not directly contribute to DNS-layer security or centralized threat correlation.