nerdexam
Cisco

350-701 · Question #632

An organization wants to reduce their attack surface for cloud applications. They want to understand application communications, detect abnormal application behavior, and detect vulnerabilities…

The correct answer is A. Configure Cisco Tetration to detect anomalies and vulnerabilities. To understand cloud application communications, detect abnormal behavior, and identify vulnerabilities to reduce the attack surface, configuring Cisco Tetration is the appropriate action.

Submitted by viktor_hu· Mar 30, 2026Cloud Security

Question

An organization wants to reduce their attack surface for cloud applications. They want to understand application communications, detect abnormal application behavior, and detect vulnerabilities within the applications. Which action accomplishes this task?

Options

  • AConfigure Cisco Tetration to detect anomalies and vulnerabilities.
  • BModify the Cisco Duo configuration to restrict access between applications.
  • CUse Cisco ISE to provide application visibility and restrict access to them.
  • DImplement Cisco Umbrella to control the access each application is granted.

How the community answered

(53 responses)
  • A
    60% (32)
  • B
    9% (5)
  • C
    25% (13)
  • D
    6% (3)

Why each option

To understand cloud application communications, detect abnormal behavior, and identify vulnerabilities to reduce the attack surface, configuring Cisco Tetration is the appropriate action.

AConfigure Cisco Tetration to detect anomalies and vulnerabilities.Correct

Cisco Tetration provides real-time visibility into application communications, detects abnormal behavior using advanced analytics, and helps identify vulnerabilities within workloads across cloud and data center environments, directly addressing all stated requirements for reducing the attack surface.

BModify the Cisco Duo configuration to restrict access between applications.

Cisco Duo primarily provides multi-factor authentication and secure access for users to applications and resources, not deep visibility into application communications, abnormal application behavior, or application vulnerability detection.

CUse Cisco ISE to provide application visibility and restrict access to them.

Cisco ISE (Identity Services Engine) focuses on network access control, providing visibility into users and devices connecting to the network and enforcing access policies, but it does not offer the granular application communication analysis or vulnerability detection capabilities within applications that Tetration provides.

DImplement Cisco Umbrella to control the access each application is granted.

Cisco Umbrella provides security at the DNS layer, protecting against malware, phishing, and C2 callbacks by blocking malicious domains, but it does not offer insights into application communications, detect abnormal application behavior, or find vulnerabilities within applications.

Concept tested: Cisco Tetration capabilities

Source: https://www.cisco.com/c/en/us/products/security/tetration/index.html

Topics

#Cisco Tetration#Workload Protection#Anomaly Detection#Vulnerability Management

Community Discussion

No community discussion yet for this question.

Full 350-701 Practice