300-215 exam dumps

300-215 practice question 168 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 168

Select 2

During an incident response investigation, a security analyst needs to correlate DNS requests with suspicious activity across the network while also inspecting endpoint behavior for malware infections. Which combination of Cisco security solutions should the analyst use to achieve these goals?

  1. A

    Cisco Umbrella and Cisco Secure Endpoint

  2. B

    Cisco Firepower and Cisco Secure Network Analytics

  3. C

    Cisco Umbrella and Cisco Firepower

  4. D

    Cisco Secure Endpoint and Cisco Secure Network Analytics

  5. E

    Cisco Umbrella and Cisco Secure Network Analytics

Show answer and explanation

Correct answers: A, E

Explanation

In this scenario, the analyst needs to track DNS activity and inspect endpoint behavior. Cisco Umbrella offers DNS-layer threat intelligence, while Cisco Secure Endpoint provides endpoint monitoring and malware detection. Alternatively, Cisco Umbrella and Cisco Secure Network Analytics can work together to correlate DNS requests with suspicious network behavior. These solutions collectively address the goals of the investigation.

  • A. Correct.

    Cisco Umbrella provides visibility into DNS requests and blocks malicious domains, while Cisco Secure Endpoint monitors and analyzes endpoint behavior for malware infections, making this combination effective for the described scenario.

  • B. Incorrect.

    Cisco Firepower is primarily focused on intrusion prevention, firewall capabilities, and deep packet inspection, which does not directly address DNS activity or endpoint behavior monitoring.

  • C. Incorrect.

    While Cisco Umbrella can track DNS activity, Cisco Firepower focuses on intrusion detection and prevention, which is less relevant for endpoint behavior analysis in this scenario.

  • D. Incorrect.

    Cisco Secure Endpoint provides visibility into endpoint activities, but Cisco Secure Network Analytics primarily focuses on network traffic and behavioral anomalies rather than DNS activity.

  • E. Correct.

    Cisco Umbrella provides DNS-level threat intelligence, and Cisco Secure Network Analytics detects network anomalies, making this combination suitable for correlating DNS requests with network behavior.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam