500-651 · Question #4
Which two options are attack vectors of the threat-centric defense? (Choose two)
The correct answer is C. Mobile E. Cloud apps. Mobile (C) and Cloud apps (E) are correct because the threat-centric defense model - prominent in Cisco's security framework - focuses on modern, pervasive attack surfaces that extend beyond the traditional network perimeter; mobile devices are prime targets due to their…
Question
Which two options are attack vectors of the threat-centric defense? (Choose two)
Options
- AVoicemail
- BBackups
- CMobile
- DVideo surveillance
- ECloud apps
How the community answered
(42 responses)- A7% (3)
- B5% (2)
- C69% (29)
- D19% (8)
Explanation
Mobile (C) and Cloud apps (E) are correct because the threat-centric defense model - prominent in Cisco's security framework - focuses on modern, pervasive attack surfaces that extend beyond the traditional network perimeter; mobile devices are prime targets due to their ubiquity and weaker security controls, while cloud apps introduce data and access risks outside organizational boundaries. Voicemail (A) is a distractor because, while vishing attacks exist, voicemail itself is not a recognized attack vector category in this framework. Backups (B) are a recovery mechanism, not an attack vector - they reduce impact but aren't a path attackers exploit in this model's categorization. Video surveillance (D), though an IoT risk in practice, is not part of the standard threat-centric attack vector taxonomy.
Memory tip: Think "MCE" - Mobile and Cloud Expand the perimeter. The wrong answers are either defensive tools (backups), legacy/niche channels (voicemail), or physical security tools (video surveillance) - none of which fit the modern, network-centric threat model being tested.
Topics
Community Discussion
No community discussion yet for this question.