300-740 · Question #13
Refer to the exhibit. An engineer must analyze the Cisco Secure Cloud Analytics report. What is occurring?
The correct answer is C. Geographically unusual remote access. Option C is correct because Cisco Secure Cloud Analytics (formerly Stealthwatch Cloud) flags geographically unusual remote access when it detects connections originating from IP addresses or regions that are anomalous for a given user or device - the exhibit would show an alert…
Question
Refer to the exhibit. An engineer must analyze the Cisco Secure Cloud Analytics report. What is occurring?
Exhibit
Options
- APersistent remote-control connections
- BDistributed DDoS attack
- CGeographically unusual remote access
- DMemory exhaustion attempt toward port 22
How the community answered
(24 responses)- A8% (2)
- B4% (1)
- C67% (16)
- D21% (5)
Explanation
Option C is correct because Cisco Secure Cloud Analytics (formerly Stealthwatch Cloud) flags geographically unusual remote access when it detects connections originating from IP addresses or regions that are anomalous for a given user or device - the exhibit would show an alert highlighting unexpected geographic origin for a remote session, not a high-volume or destructive pattern.
- A is wrong because persistent remote-control connections (e.g., C2 beaconing) would appear as repeated, low-and-slow outbound sessions to a single external host - the report would highlight unusual beacon intervals, not geographic anomalies.
- B is wrong because a distributed DDoS attack involves massive inbound traffic volume from many sources overwhelming a target - Secure Cloud Analytics would show high packet/flow counts, not a geographic login alert.
- D is wrong because a memory exhaustion attempt toward port 22 is not a recognized Secure Cloud Analytics alert category; port 22 brute-force would appear as repeated failed authentication attempts, not a memory/resource exhaustion event.
Memory tip: Think "Geo = Geography" - the word "geographically" is the giveaway. Secure Cloud Analytics correlates user behavior baselines, so a login from an unusual country/region stands out as a behavioral anomaly, which is exactly what this alert category detects.
Topics
Community Discussion
No community discussion yet for this question.
