350-201 Question 93
Select 3A company uses Cisco SecureX and Cisco Secure Network Analytics to monitor its network. Recently, the company experienced a series of phishing attacks that bypassed traditional security filters. As a cybersecurity analyst, you are tasked with applying AI-driven threat intelligence to mitigate future attacks. Which actions should you take to leverage AI-driven tools effectively in this scenario?
- A
Integrate Cisco Talos threat intelligence feed into SecureX to update phishing indicators of compromise (IOCs).
- B
Configure SecureX orchestration to automatically block IP addresses flagged with high threat scores.
- C
Manually analyze all inbound email traffic logs for phishing attempts and update firewall rules.
- D
Enable machine learning models in Cisco Secure Network Analytics to detect abnormal user behavior associated with phishing campaigns.
- E
Disable automated threat intelligence updates to manually verify all threat data before integration.
Show answer and explanation
Correct answers: A, B, D
Explanation
AI-driven tools in Cisco SecureX and Secure Network Analytics, such as integrating threat intelligence feeds, enabling orchestration for automated responses, and utilizing machine learning models, significantly improve the detection and mitigation of phishing attacks. These tools reduce manual effort and provide real-time protection by leveraging advanced analytics and automation. Disabling automated updates or relying solely on manual processes contradicts the purpose of using AI-driven security solutions.
- A. Correct.
Integrating Cisco Talos into SecureX ensures that the system is updated with the latest threat intelligence, including phishing IOCs, enhancing detection and response capabilities against such attacks.
- B. Correct.
Configuring SecureX orchestration to block high-threat IPs automates the mitigation process and leverages AI-driven threat intelligence to prevent malicious traffic from reaching the network.
- C. Incorrect.
Manually analyzing email traffic is resource-intensive and impractical for large-scale operations. This does not leverage the AI-driven capabilities of the Cisco tools.
- D. Correct.
Enabling machine learning in Secure Network Analytics allows the system to detect unusual behavior patterns, such as those seen in phishing campaigns, improving proactive threat detection.
- E. Incorrect.
Disabling automated threat intelligence updates undermines the purpose of using AI-driven tools and decreases the system's ability to respond to emerging threats.