350-201 exam dumps

350-201 practice question 96 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 96

Select 3

A security analyst working for an organization notices an unusual spike in outbound traffic from multiple endpoints on the network. The analyst decides to use Cisco SecureX Threat Response and its AI-driven threat intelligence capabilities to investigate. Which actions should the analyst take using SecureX to identify and mitigate the threat?

  1. A

    Leverage AI-driven insights in SecureX to identify malicious domains or IP addresses associated with the traffic.

  2. B

    Manually cross-reference the traffic patterns with external threat intelligence feeds.

  3. C

    Utilize SecureX to correlate endpoint behaviors and malicious indicators across the environment.

  4. D

    Deploy AI-driven automated playbooks in SecureX to isolate affected endpoints immediately.

  5. E

    Disable SecureX AI capabilities temporarily to ensure manual control over the investigation process.

Show answer and explanation

Correct answers: A, C, D

Explanation

Cisco SecureX Threat Response leverages AI-driven threat intelligence to streamline threat investigation and mitigation. In this scenario, using AI insights to identify malicious indicators, correlating endpoint behaviors, and deploying automated responses are key steps to efficiently handle the spike in outbound traffic. Manual or disabling actions undermine the tool's purpose and delay effective resolution.

  • A. Correct.

    SecureX uses AI-driven threat intelligence to detect and highlight malicious domains or IPs, making this a critical step in identifying the source of unusual traffic.

  • B. Incorrect.

    Manually cross-referencing traffic patterns with external feeds is inefficient and contradicts the purpose of AI-driven tools, which automate such tasks.

  • C. Correct.

    SecureX can correlate behaviors and indicators across endpoints to provide a holistic view of the threat, which is essential for effective investigation.

  • D. Correct.

    Using automated playbooks in SecureX allows for faster response times, such as isolating affected endpoints, which limits the threat's spread.

  • E. Incorrect.

    Disabling AI capabilities would hinder the efficiency of the investigation, as SecureX's strength lies in its AI-driven automation and correlation features.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam