350-201 exam dumps

350-201 practice question 9 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 9

Select 3

An organization has observed a spike in suspicious outbound traffic from multiple endpoints. According to the incident response playbook, the team needs to analyze network traffic for potential data exfiltration and identify the affected endpoints. Which tools should be used to fulfill the requirements outlined in the playbook?

  1. A

    NetFlow or Secure Network Analytics

  2. B

    Cisco Advanced Malware Protection (AMP) for Endpoints

  3. C

    Wireshark or packet capture tools

  4. D

    Cisco Umbrella

  5. E

    Cisco Identity Services Engine (ISE)

  6. F

    Endpoint Detection and Response (EDR) tools

Show answer and explanation

Correct answers: A, C, F

Explanation

To address the playbook scenario, tools like NetFlow or Secure Network Analytics, Wireshark, and EDR are essential. NetFlow or Secure Network Analytics offers high-level visibility into network traffic, Wireshark provides granular packet-level analysis, and EDR tools help investigate and remediate affected endpoints. These tools together fulfill the requirements of detecting data exfiltration and identifying impacted endpoints.

  • A. Correct.

    NetFlow or Secure Network Analytics provides visibility into network traffic patterns and can help identify anomalous or suspicious outbound traffic indicative of data exfiltration.

  • B. Incorrect.

    Cisco Advanced Malware Protection (AMP) for Endpoints focuses on malware detection and remediation on endpoints, but it does not analyze network traffic for data exfiltration.

  • C. Correct.

    Wireshark or packet capture tools allow for detailed inspection of network traffic, making them essential for analyzing data exfiltration incidents.

  • D. Incorrect.

    Cisco Umbrella provides DNS-layer security and blocks malicious domains, but it is not designed for in-depth traffic analysis during an incident response.

  • E. Incorrect.

    Cisco Identity Services Engine (ISE) focuses on network access control and policy enforcement but does not provide tools for analyzing network traffic or endpoints during incidents.

  • F. Correct.

    Endpoint Detection and Response (EDR) tools help identify and investigate compromised endpoints, making them useful for addressing affected endpoints as per the playbook.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam