350-701 · Question #603
Which Cisco security solution stops exfiltration using HTTPS?
The correct answer is A. Cisco CTA. Cisco CTA (Cognitive Threat Analytics) is correct because it uses behavioral analysis and machine learning to detect and block data exfiltration over encrypted HTTPS traffic - without needing to decrypt it. It identifies anomalous patterns (unusual volumes, destinations…
Question
Which Cisco security solution stops exfiltration using HTTPS?
Options
- ACisco CTA
- BCisco FTD
- CCisco AnyConnect
- DCisco ASA
How the community answered
(29 responses)- A79% (23)
- B10% (3)
- C7% (2)
- D3% (1)
Explanation
Cisco CTA (Cognitive Threat Analytics) is correct because it uses behavioral analysis and machine learning to detect and block data exfiltration over encrypted HTTPS traffic - without needing to decrypt it. It identifies anomalous patterns (unusual volumes, destinations, timing) in encrypted flows, making it uniquely suited to catch HTTPS-based exfiltration that other tools miss.
Why the distractors are wrong:
- B. Cisco FTD is a next-gen firewall/IPS platform focused on general threat prevention; while it can inspect traffic, it's not specifically designed to stop HTTPS exfiltration through encrypted-traffic behavioral analysis.
- C. Cisco AnyConnect is a VPN client for secure remote access - it creates encrypted tunnels, not monitors them for exfiltration.
- D. Cisco ASA is a traditional stateful firewall; it enforces access control but lacks the behavioral intelligence to detect covert HTTPS exfiltration.
Memory tip: Think "Covert Traffic Analysis" - CTA watches how data flows over HTTPS (behavior, volume, destination anomalies) rather than what's inside it, making it the right tool when exfiltration hides inside encrypted channels.
Topics
Community Discussion
No community discussion yet for this question.