nerdexam
Cisco

350-201 · Question #116

An engineer notices that every Sunday night, there is a two-hour period with a large load of network activity. Upon further investigation, the engineer finds that the activity is from locations…

The correct answer is C. Define the access points using StealthWatch or SIEM logs, understand services being offered. Recurring anomalous global network traffic requires systematic investigation using monitoring tools to identify access points and characterize the activity before any mitigation is applied.

Security Monitoring

Question

An engineer notices that every Sunday night, there is a two-hour period with a large load of network activity. Upon further investigation, the engineer finds that the activity is from locations around the globe outside the organization's service area. What are the next steps the engineer must take?

Options

  • AAssign the issue to the incident handling provider because no suspicious activity has been
  • BReview the SIEM and FirePower logs, block all traffic, and document the results of calling the call
  • CDefine the access points using StealthWatch or SIEM logs, understand services being offered
  • DTreat it as a false positive, and accept the SIEM issue as valid to avoid alerts from triggering on

How the community answered

(29 responses)
  • A
    7% (2)
  • B
    10% (3)
  • C
    55% (16)
  • D
    28% (8)

Why each option

Recurring anomalous global network traffic requires systematic investigation using monitoring tools to identify access points and characterize the activity before any mitigation is applied.

AAssign the issue to the incident handling provider because no suspicious activity has been

Assigning to an incident handler without any investigation ignores a repeating pattern of suspicious global traffic that warrants active analysis.

BReview the SIEM and FirePower logs, block all traffic, and document the results of calling the call

Blocking all traffic is a premature containment action that should only follow investigation; acting without understanding the traffic could disrupt legitimate services.

CDefine the access points using StealthWatch or SIEM logs, understand services being offeredCorrect

Using StealthWatch or SIEM logs to define the access points and understand which services are being accessed is the correct first step because it provides the forensic visibility needed to determine whether the activity is malicious, misconfigured, or a legitimate but unexpected workload. This evidence-based approach follows proper incident handling methodology by scoping and understanding the issue before taking action that could disrupt legitimate services.

DTreat it as a false positive, and accept the SIEM issue as valid to avoid alerts from triggering on

Accepting the alert as a false positive without investigation dismisses a consistent anomaly pattern and violates basic incident handling discipline.

Concept tested: Network anomaly investigation using StealthWatch and SIEM logs

Source: https://www.cisco.com/c/en/us/products/security/stealthwatch/index.html

Topics

#anomalous network activity#SIEM investigation#StealthWatch#threat hunting

Community Discussion

No community discussion yet for this question.

Full 350-201 Practice