300-445 exam dumps

300-445 practice question 172 of 255

Designing and Implementing Enterprise Network Assurance. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-445 Question 172

Single answer

A network engineer is using a network assurance platform to analyze traffic patterns and identify potential anomalies in an enterprise network. The platform has flagged a sudden increase in traffic from a specific subnet. Upon further investigation, the engineer observes that the majority of the traffic is due to repetitive DNS queries to an external server. Which data analysis technique would be most effective in confirming whether this is a potential DNS amplification attack?

  1. A

    Performing a time-series analysis on DNS query volume from the subnet

  2. B

    Using predictive modeling to estimate future DNS query trends

  3. C

    Comparing the DNS traffic pattern against historical baselines

  4. D

    Conducting a packet capture and analyzing payload contents for malicious data

Show answer and explanation

Correct answer: C

Explanation

To confirm whether the sudden increase in DNS queries is part of a DNS amplification attack, comparing current traffic patterns against historical baselines is the most effective method. This approach helps identify deviations from normal behavior, which is a key indicator of potential anomalies or attacks in network assurance.

  • A. Incorrect.

    Time-series analysis is useful for identifying patterns over time, but it does not inherently compare query patterns to historical baselines, which is critical for anomaly detection in this case.

  • B. Incorrect.

    Predictive modeling focuses on estimating future trends rather than analyzing current anomalies or comparing against known baselines.

  • C. Correct.

    Comparing the DNS traffic pattern against historical baselines allows the engineer to determine whether the current behavior is anomalous compared to normal traffic patterns, making it the most effective technique in this context.

  • D. Incorrect.

    Packet capture and payload analysis are useful for detailed inspection of traffic, but they are not the most efficient method for identifying trends or anomalies in DNS query volumes.

Timed practice exam

Take a 300-445 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam