300-215 exam dumps

300-215 practice question 92 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 92

Select 3

During a routine network traffic analysis using Cisco Secure Network Analytics (formerly Stealthwatch), you notice a significant increase in outbound traffic to an external IP address that is not part of your organization's normal communication patterns. What steps should you take to identify whether this behavior is indicative of an anomaly or a potential compromise?

  1. A

    Compare the observed traffic volume against historical baselines for similar time periods.

  2. B

    Immediately block all outbound traffic to the external IP address without further investigation.

  3. C

    Examine the flow records for the specific IP address to identify unusual patterns such as unexpected protocols or ports.

  4. D

    Correlate the external IP address with threat intelligence feeds to check if it is associated with malicious activity.

  5. E

    Assume the activity is normal unless confirmed by intrusion detection system (IDS) alerts.

Show answer and explanation

Correct answers: A, C, D

Explanation

Network traffic analysis for anomaly detection involves systematically identifying deviations from normal behavior. Steps like comparing against baselines, analyzing flow records, and utilizing threat intelligence are essential for determining if the observed traffic is anomalous or malicious. Premature actions, such as blocking traffic without investigation, or assumptions of normalcy without evidence, can hinder effective incident response.

  • A. Correct.

    Analyzing the traffic against historical baselines is critical for determining whether this behavior deviates from normal patterns, a key step in anomaly detection.

  • B. Incorrect.

    Blocking traffic immediately without investigation can disrupt legitimate operations and is not a recommended first step in forensic analysis or incident response.

  • C. Correct.

    Examining flow records helps in identifying unusual communication patterns, such as unexpected ports or protocols, which can be indicative of malicious activity.

  • D. Correct.

    Correlating the IP address with threat intelligence feeds is an effective way to determine if the external address is known for malicious activity, aiding in anomaly detection.

  • E. Incorrect.

    Assuming the activity is normal without proper investigation contradicts the principles of effective forensic analysis and incident response.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam