nerdexam
Cisco

500-651 · Question #74

Which feature of CTA can separate statistically normal traffic form anomalous traffic?

The correct answer is C. Anomaly detection. Anomaly detection (C) is the CTA feature specifically designed to establish statistical baselines of normal network behavior and flag traffic that deviates from those baselines - making it the direct answer to "separating statistically normal from anomalous traffic." Why the…

Network Security

Question

Which feature of CTA can separate statistically normal traffic form anomalous traffic?

Options

  • AURL filtering
  • BTrust modeling
  • CAnomaly detection
  • DEvent classification

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    7% (2)
  • C
    89% (25)

Explanation

Anomaly detection (C) is the CTA feature specifically designed to establish statistical baselines of normal network behavior and flag traffic that deviates from those baselines - making it the direct answer to "separating statistically normal from anomalous traffic."

Why the distractors are wrong:

  • A (URL filtering) blocks or allows traffic based on URL categories/reputation lists - it applies policy rules, not statistical analysis.
  • B (Trust modeling) scores the trustworthiness of users or devices over time but is not the mechanism that performs the statistical normal-vs-anomalous separation itself.
  • D (Event classification) categorizes security events after they are detected; it labels threats but doesn't do the statistical comparison that surfaces them.

Memory tip: Think of the word "anomaly" - it literally means "something deviating from the norm." If a question asks about separating normal from abnormal (or statistical baselines), the answer will almost always be anomaly detection.

Topics

#anomaly detection#CTA#traffic analysis#threat detection

Community Discussion

No community discussion yet for this question.

Full 500-651 Practice