300-215 exam dumps

300-215 practice question 95 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 95

Select 3

During an investigation of unusual network activity, you are tasked with identifying anomalies in network traffic using Cisco Stealthwatch. Which of the following actions would help you detect potential anomalies effectively?

  1. A

    Analyze the top talker hosts by bandwidth usage to identify unusual spikes.

  2. B

    Review traffic baselines for deviations in expected protocol usage.

  3. C

    Search for encrypted traffic and immediately block all such connections.

  4. D

    Examine traffic flows with unusually long durations or high packet counts.

  5. E

    Filter out all traffic from known trusted sources to focus only on unknown hosts.

Show answer and explanation

Correct answers: A, B, D

Explanation

When conducting network traffic analysis for anomaly detection using tools like Cisco Stealthwatch, it is critical to focus on key indicators of anomalous behavior, such as bandwidth usage, deviations from traffic baselines, and unusual traffic flow characteristics. These methods provide insights into potential threats while avoiding overly restrictive or exclusionary approaches that could overlook critical details or cause unnecessary disruptions.

  • A. Correct.

    Analyzing top talker hosts by bandwidth usage helps identify hosts that are consuming unusual amounts of bandwidth, which could indicate anomalies such as data exfiltration or a DDoS attack.

  • B. Correct.

    Reviewing traffic baselines for deviations in expected protocol usage allows you to identify unexpected behavior, such as the use of unauthorized protocols, which could signal malicious activity.

  • C. Incorrect.

    Blocking all encrypted traffic is not a valid approach, as it may disrupt normal operations. Instead, encryption should be analyzed in the context of its normal usage patterns.

  • D. Correct.

    Examining traffic flows with unusually long durations or high packet counts can reveal anomalies such as persistent connections used for unauthorized data transfer or other malicious activity.

  • E. Incorrect.

    Filtering out all traffic from trusted sources is not recommended because trusted sources can also be compromised. Comprehensive analysis should include all traffic.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam