350-201 · Question #79
Refer to the exhibit. Cisco Rapid Threat Containment using Cisco Secure Network Analytics (Stealthwatch) and ISE detects the threat of malware-infected 802.1x authenticated endpoints and places that…
The correct answer is B. event data and syslog data. In the Cisco Rapid Threat Containment solution, the Stealthwatch Management Console (SMC) correlates event data from ISE and syslog data from network devices to identify malware on authenticated endpoints.
Question
Refer to the exhibit. Cisco Rapid Threat Containment using Cisco Secure Network Analytics (Stealthwatch) and ISE detects the threat of malware-infected 802.1x authenticated endpoints and places that endpoint into a Quarantine VLAN using Adaptive Network Control policy. Which telemetry feeds were correlated with SMC to identify the malware?
Exhibit
Options
- ANetFlow and event data
- Bevent data and syslog data
- CSNMP and syslog data
- DNetFlow and SNMP
How the community answered
(48 responses)- A4% (2)
- B71% (34)
- C17% (8)
- D8% (4)
Why each option
In the Cisco Rapid Threat Containment solution, the Stealthwatch Management Console (SMC) correlates event data from ISE and syslog data from network devices to identify malware on authenticated endpoints.
NetFlow data is the native data source that Stealthwatch itself collects and processes internally from network devices, so it is not a separate feed correlated externally with SMC.
Cisco ISE sends endpoint event data (authentication, authorization, and posture events) to the SMC via pxGrid integration, providing identity context for 802.1x authenticated endpoints. Syslog data from network infrastructure devices is also forwarded to and correlated by the SMC to detect anomalous behavior associated with malware. Together these two feeds allow the SMC to link network events with specific authenticated endpoint identities.
SNMP is a network management and monitoring protocol used for device polling and traps, and is not a primary telemetry feed used by Stealthwatch SMC for malware correlation.
NetFlow is natively processed within Stealthwatch rather than being an external feed correlated with SMC, and SNMP does not provide the behavioral telemetry needed for malware detection in this architecture.
Concept tested: Cisco Stealthwatch and ISE RTC telemetry correlation
Source: https://www.cisco.com/c/en/us/solutions/enterprise-networks/rapid-threat-containment/index.html
Topics
Community Discussion
No community discussion yet for this question.
