300-215 exam dumps

300-215 practice question 94 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 94

Single answer

You are conducting network traffic analysis using Cisco Secure Network Analytics (formerly Stealthwatch) to detect anomalies. During your investigation, you notice an unusually high volume of outbound traffic from a single internal host to an unknown external IP address over an uncommon port. What is the most appropriate next step to determine if this activity is malicious?

  1. A

    Check the host's internal activity to identify any unusual processes or connections.

  2. B

    Immediately blacklist the external IP address to block the traffic.

  3. C

    Analyze historical traffic patterns of this host to determine if this behavior is normal.

  4. D

    Perform packet capture and deep packet inspection to examine the content of the traffic.

Show answer and explanation

Correct answer: C

Explanation

When detecting anomalies in network traffic, it is important to first establish whether the activity deviates from the normal behavior of the host. Cisco Secure Network Analytics provides historical data and behavioral baselines that can help determine if the observed traffic is truly anomalous. Jumping directly to blocking or deep packet inspection might lead to premature conclusions or unnecessary disruptions.

  • A. Incorrect.

    This is a valid step, but it should not be the first action. Internal host analysis is better utilized after confirming that the behavior is indeed anomalous or malicious.

  • B. Incorrect.

    Blocking the external IP address without understanding the context of the traffic could disrupt legitimate communications and may not address the root cause of the issue.

  • C. Correct.

    Analyzing historical traffic patterns is a critical step to determine if the observed behavior is truly anomalous or part of normal operational activity.

  • D. Incorrect.

    Packet capture and deep packet inspection is a detailed analysis step that can be performed later, but it may not be the most efficient starting point for anomaly detection.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam