350-201 exam dumps

350-201 practice question 130 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 130

Single answer

Your organization uses a Security Information and Event Management (SIEM) tool to monitor and analyze security events. During an investigation of a potential insider threat, you notice that a user has been accessing sensitive information from multiple devices in different geographic locations within a short time frame. Which SIEM feature would be most useful in detecting this type of anomalous activity?

  1. A

    Log aggregation and correlation

  2. B

    User behavior analytics (UBA)

  3. C

    Threat intelligence integration

  4. D

    Automated incident response

Show answer and explanation

Correct answer: B

Explanation

SIEM tools use various features to enhance security data analytics. In this scenario, detecting anomalous user activity, such as accessing data from multiple locations in a short time frame, is best accomplished using User Behavior Analytics (UBA). UBA employs machine learning and statistical models to identify deviations from normal behavior, making it the most relevant feature for this use case.

  • A. Incorrect.

    Log aggregation and correlation collect and combine logs from different sources for analysis, but it does not inherently identify behavioral anomalies such as unusual user activity.

  • B. Correct.

    User behavior analytics (UBA) is specifically designed to detect anomalies in user actions, such as unusual access patterns or suspicious behaviors, making it highly relevant for detecting insider threats.

  • C. Incorrect.

    Threat intelligence integration helps identify external threats based on threat feeds and indicators of compromise (IOCs), but it does not focus on user behavior within the organization.

  • D. Incorrect.

    Automated incident response helps respond to detected threats, but it does not contribute to the detection of anomalous user activity itself.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam