nerdexam
Cisco

350-201 · Question #79

Refer to the exhibit. Cisco Rapid Threat Containment using Cisco Secure Network Analytics (Stealthwatch) and ISE detects the threat of malware-infected 802.1x authenticated endpoints and places that…

The correct answer is B. event data and syslog data. In the Cisco Rapid Threat Containment solution, the Stealthwatch Management Console (SMC) correlates event data from ISE and syslog data from network devices to identify malware on authenticated endpoints.

Security Monitoring

Question

Refer to the exhibit. Cisco Rapid Threat Containment using Cisco Secure Network Analytics (Stealthwatch) and ISE detects the threat of malware-infected 802.1x authenticated endpoints and places that endpoint into a Quarantine VLAN using Adaptive Network Control policy. Which telemetry feeds were correlated with SMC to identify the malware?

Exhibit

350-201 question #79 exhibit

Options

  • ANetFlow and event data
  • Bevent data and syslog data
  • CSNMP and syslog data
  • DNetFlow and SNMP

How the community answered

(48 responses)
  • A
    4% (2)
  • B
    71% (34)
  • C
    17% (8)
  • D
    8% (4)

Why each option

In the Cisco Rapid Threat Containment solution, the Stealthwatch Management Console (SMC) correlates event data from ISE and syslog data from network devices to identify malware on authenticated endpoints.

ANetFlow and event data

NetFlow data is the native data source that Stealthwatch itself collects and processes internally from network devices, so it is not a separate feed correlated externally with SMC.

Bevent data and syslog dataCorrect

Cisco ISE sends endpoint event data (authentication, authorization, and posture events) to the SMC via pxGrid integration, providing identity context for 802.1x authenticated endpoints. Syslog data from network infrastructure devices is also forwarded to and correlated by the SMC to detect anomalous behavior associated with malware. Together these two feeds allow the SMC to link network events with specific authenticated endpoint identities.

CSNMP and syslog data

SNMP is a network management and monitoring protocol used for device polling and traps, and is not a primary telemetry feed used by Stealthwatch SMC for malware correlation.

DNetFlow and SNMP

NetFlow is natively processed within Stealthwatch rather than being an external feed correlated with SMC, and SNMP does not provide the behavioral telemetry needed for malware detection in this architecture.

Concept tested: Cisco Stealthwatch and ISE RTC telemetry correlation

Source: https://www.cisco.com/c/en/us/solutions/enterprise-networks/rapid-threat-containment/index.html

Topics

#Cisco Stealthwatch#ISE#network telemetry#threat containment

Community Discussion

No community discussion yet for this question.

Full 350-201 Practice