350-201 Question 45
Select 3A security analyst is investigating unusual outbound traffic from a corporate network. After analyzing captured packets, they discover a suspicious domain repeatedly contacted by an internal host. To mitigate this threat, which Cisco security technologies and techniques would be most effective in blocking such communication?
- A
Cisco Umbrella for DNS-layer security
- B
Cisco Secure Malware Analytics (Threat Grid) for malware sandboxing
- C
Cisco Secure Firewall with URL filtering
- D
Cisco Secure Endpoint with retrospective security
- E
Cisco ISE for network segmentation
Show answer and explanation
Correct answers: A, C, D
Explanation
To address the suspicious domain communication, Cisco Umbrella can block DNS resolutions to the domain, Cisco Secure Firewall can filter and block traffic based on URL policies, and Cisco Secure Endpoint can stop malicious activities on endpoints. These technologies work together to comprehensively mitigate the threat.
- A. Correct.
Cisco Umbrella can block access to malicious or suspicious domains at the DNS layer, preventing further communication with the domain.
- B. Incorrect.
Cisco Secure Malware Analytics is primarily used to analyze and sandbox malware rather than directly block domain communications.
- C. Correct.
Cisco Secure Firewall with URL filtering can block outbound communication with suspicious domains based on URL categories and policies.
- D. Correct.
Cisco Secure Endpoint provides retrospective security, which can identify malicious activities in endpoints and stop further communication.
- E. Incorrect.
Cisco ISE is primarily used for network access control and segmentation, which does not directly address the issue of blocking communication with a specific domain.