200-201 · Question #111
Refer to the exhibit. What is the potential threat identified in this Stealthwatch dashboard?
The correct answer is D. Host 10.201.3.149 is receiving almost 19 times more data than is being sent to host 152.46.6.91. The Stealthwatch dashboard identifies a "Data Hoarding" anomaly where host 10.201.3.149 is receiving significantly more data from 152.46.6.91 than it is sending to it, indicating a potential threat like data exfiltration or unauthorized large downloads.
Question
Refer to the exhibit. What is the potential threat identified in this Stealthwatch dashboard?
Exhibit
Options
- AHost 10.201.3.149 is sending data to 152.46.6.91 using TCP/443.
- BHost 152.46.6.91 is being identified as a watchlist country for data transfer.
- CTraffic to 152.46.6.149 is being denied by an Advanced Network Control policy.
- DHost 10.201.3.149 is receiving almost 19 times more data than is being sent to host 152.46.6.91.
How the community answered
(34 responses)- A9% (3)
- B18% (6)
- C3% (1)
- D71% (24)
Why each option
The Stealthwatch dashboard identifies a "Data Hoarding" anomaly where host 10.201.3.149 is receiving significantly more data from 152.46.6.91 than it is sending to it, indicating a potential threat like data exfiltration or unauthorized large downloads.
While the alert might be based on traffic over TCP/443, merely stating that traffic is occurring on that port is a factual observation and not the potential threat identified by the alarm, which is the data imbalance.
The exhibit does not contain any information about 152.46.6.91 being identified as a watchlist country; the alert is about a data transfer imbalance.
The exhibit refers to IP 152.46.6.91, not 152.46.6.149, and there is no mention of an "Advanced Network Control policy" denying traffic.
The exhibit explicitly states, "Host 10.201.3.149 is receiving almost 19 times more data from 152.46.6.91 than is being sent to it," which is the direct description of the identified "Data Hoarding" anomaly. This disproportionate data transfer ratio is what the Stealthwatch system flags as a potential security incident, as it could indicate data exfiltration or an unusually large download.
Concept tested: Network traffic anomaly detection (Stealthwatch)
Source: https://www.cisco.com/c/en/us/products/security/secure-network-analytics/index.html
Topics
Community Discussion
No community discussion yet for this question.
