300-215 Question 168
Select 2During an incident response investigation, a security analyst needs to correlate DNS requests with suspicious activity across the network while also inspecting endpoint behavior for malware infections. Which combination of Cisco security solutions should the analyst use to achieve these goals?
- A
Cisco Umbrella and Cisco Secure Endpoint
- B
Cisco Firepower and Cisco Secure Network Analytics
- C
Cisco Umbrella and Cisco Firepower
- D
Cisco Secure Endpoint and Cisco Secure Network Analytics
- E
Cisco Umbrella and Cisco Secure Network Analytics
Show answer and explanation
Correct answers: A, E
Explanation
In this scenario, the analyst needs to track DNS activity and inspect endpoint behavior. Cisco Umbrella offers DNS-layer threat intelligence, while Cisco Secure Endpoint provides endpoint monitoring and malware detection. Alternatively, Cisco Umbrella and Cisco Secure Network Analytics can work together to correlate DNS requests with suspicious network behavior. These solutions collectively address the goals of the investigation.
- A. Correct.
Cisco Umbrella provides visibility into DNS requests and blocks malicious domains, while Cisco Secure Endpoint monitors and analyzes endpoint behavior for malware infections, making this combination effective for the described scenario.
- B. Incorrect.
Cisco Firepower is primarily focused on intrusion prevention, firewall capabilities, and deep packet inspection, which does not directly address DNS activity or endpoint behavior monitoring.
- C. Incorrect.
While Cisco Umbrella can track DNS activity, Cisco Firepower focuses on intrusion detection and prevention, which is less relevant for endpoint behavior analysis in this scenario.
- D. Incorrect.
Cisco Secure Endpoint provides visibility into endpoint activities, but Cisco Secure Network Analytics primarily focuses on network traffic and behavioral anomalies rather than DNS activity.
- E. Correct.
Cisco Umbrella provides DNS-level threat intelligence, and Cisco Secure Network Analytics detects network anomalies, making this combination suitable for correlating DNS requests with network behavior.