nerdexam
Cisco

300-740 · Question #25

Refer to the exhibit. An engineer is troubleshooting an incident by using Cisco Secure Cloud Analytics. What is the cause of the issue?

The correct answer is C. An FTP client was installed on a domain controller. Cisco Secure Cloud Analytics detects behavioral anomalies by modeling what "normal" looks like for each device type. A domain controller has a well-defined role - authenticating users and managing directory services - so FTP client traffic originating from it is a clear…

Visibility and Assurance

Question

Refer to the exhibit. An engineer is troubleshooting an incident by using Cisco Secure Cloud Analytics. What is the cause of the issue?

Exhibits

300-740 question #25 exhibit 1
300-740 question #25 exhibit 2

Options

  • AAn attacker installed an SSH server on the host.
  • BAn attacker opened port 22 on the host.
  • CAn FTP client was installed on a domain controller.
  • DAn FTP client was installed on a workstation.

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    11% (3)
  • C
    82% (23)
  • D
    4% (1)

Explanation

Cisco Secure Cloud Analytics detects behavioral anomalies by modeling what "normal" looks like for each device type. A domain controller has a well-defined role - authenticating users and managing directory services - so FTP client traffic originating from it is a clear role-anomaly alert, which is exactly what the exhibit highlights.

Why C is correct: Domain controllers should never initiate FTP sessions; this behavior deviates sharply from their expected baseline. Secure Cloud Analytics flags it as suspicious precisely because FTP activity is outside the normal behavioral model for that device role, suggesting unauthorized software was installed.

Why the distractors are wrong:

  • A & B describe SSH-related activity (port 22/SSH server), but the exhibit's anomaly involves FTP, not SSH - these are plausible-sounding threats but don't match the evidence shown.
  • D is tempting because FTP clients are anomalous, but the critical detail is where - a workstation occasionally running FTP is far less alarming than a domain controller doing so, and Secure Cloud Analytics specifically flags the DC context.

Memory tip: Remember "Wrong role = Red flag." Domain controllers authenticate - they don't FTP. If a DC does anything outside authentication/DNS/replication, behavioral analytics will catch it. Think: Domain Controller doing FTP = Definitely Compromised Flag.

Topics

#Cloud Analytics#Threat Detection#Domain Controller Security#Anomalous Activity

Community Discussion

No community discussion yet for this question.

Full 300-740 Practice