350-201 Question 11
Select 3During a cybersecurity incident, a playbook recommends isolating a potentially compromised endpoint and analyzing its network traffic to identify malicious activity. Which combination of tools would be most appropriate to execute this playbook scenario?
- A
Cisco AMP for Endpoints
- B
Cisco Umbrella
- C
Wireshark
- D
Cisco Secure Network Analytics (Stealthwatch)
- E
Cisco Duo
Show answer and explanation
Correct answers: A, C, D
Explanation
To execute the playbook scenario of isolating a compromised endpoint and analyzing its network traffic, you need tools that can isolate the endpoint (Cisco AMP for Endpoints) and analyze network traffic for malicious activity (Wireshark and Cisco Secure Network Analytics). These tools work in conjunction to contain the threat and gather actionable insights, while others like Cisco Umbrella and Cisco Duo do not align with the specific requirements of this scenario.
- A. Correct.
Cisco AMP for Endpoints is used to isolate an endpoint and prevent further malicious activity, making it a key tool for executing this playbook scenario.
- B. Incorrect.
Cisco Umbrella primarily focuses on DNS-layer security and blocking domain-based threats. It is not used for endpoint isolation or traffic analysis.
- C. Correct.
Wireshark is a packet analysis tool, which is essential for analyzing network traffic in this scenario.
- D. Correct.
Cisco Secure Network Analytics (Stealthwatch) is used for monitoring and analyzing network traffic to detect potential malicious activity, aligning with the playbook's requirements.
- E. Incorrect.
Cisco Duo provides multi-factor authentication and access control. It is not relevant for endpoint isolation or traffic analysis.