350-701 · Question #515
Which type of data does the Cisco Stealthwatch system collect and analyze from routers, switches, and firewalls?
The correct answer is D. NetFlow. Cisco Stealthwatch primarily collects and analyzes NetFlow data from network devices such as routers, switches, and firewalls to provide network visibility and security monitoring.
Question
Which type of data does the Cisco Stealthwatch system collect and analyze from routers, switches, and firewalls?
Options
- ANTP
- Bsyslog
- CSNMP
- DNetFlow
How the community answered
(41 responses)- A5% (2)
- B2% (1)
- D93% (38)
Why each option
Cisco Stealthwatch primarily collects and analyzes NetFlow data from network devices such as routers, switches, and firewalls to provide network visibility and security monitoring.
NTP (Network Time Protocol) is used for clock synchronization and is not the primary data source for network traffic analysis in Stealthwatch.
Syslog is for sending event messages (logs) to a central server; while Stealthwatch might integrate with syslog, its primary data source for network flow analysis is not syslog.
SNMP (Simple Network Management Protocol) is used for managing and monitoring device status and performance, but it does not provide the detailed flow information that Stealthwatch relies on.
Cisco Stealthwatch (now Cisco Secure Network Analytics) is specifically designed to consume and analyze NetFlow (and IPFIX) records. These records provide rich telemetry about network traffic flows, which Stealthwatch uses for anomaly detection, threat hunting, and security analytics.
Concept tested: Cisco Stealthwatch data collection
Source: https://www.cisco.com/c/en/us/products/security/stealthwatch/index.html
Topics
Community Discussion
No community discussion yet for this question.