350-201 Question 96
Select 3A security analyst working for an organization notices an unusual spike in outbound traffic from multiple endpoints on the network. The analyst decides to use Cisco SecureX Threat Response and its AI-driven threat intelligence capabilities to investigate. Which actions should the analyst take using SecureX to identify and mitigate the threat?
- A
Leverage AI-driven insights in SecureX to identify malicious domains or IP addresses associated with the traffic.
- B
Manually cross-reference the traffic patterns with external threat intelligence feeds.
- C
Utilize SecureX to correlate endpoint behaviors and malicious indicators across the environment.
- D
Deploy AI-driven automated playbooks in SecureX to isolate affected endpoints immediately.
- E
Disable SecureX AI capabilities temporarily to ensure manual control over the investigation process.
Show answer and explanation
Correct answers: A, C, D
Explanation
Cisco SecureX Threat Response leverages AI-driven threat intelligence to streamline threat investigation and mitigation. In this scenario, using AI insights to identify malicious indicators, correlating endpoint behaviors, and deploying automated responses are key steps to efficiently handle the spike in outbound traffic. Manual or disabling actions undermine the tool's purpose and delay effective resolution.
- A. Correct.
SecureX uses AI-driven threat intelligence to detect and highlight malicious domains or IPs, making this a critical step in identifying the source of unusual traffic.
- B. Incorrect.
Manually cross-referencing traffic patterns with external feeds is inefficient and contradicts the purpose of AI-driven tools, which automate such tasks.
- C. Correct.
SecureX can correlate behaviors and indicators across endpoints to provide a holistic view of the threat, which is essential for effective investigation.
- D. Correct.
Using automated playbooks in SecureX allows for faster response times, such as isolating affected endpoints, which limits the threat's spread.
- E. Incorrect.
Disabling AI capabilities would hinder the efficiency of the investigation, as SecureX's strength lies in its AI-driven automation and correlation features.