nerdexam
Cisco

700-551 · Question #57

Which are three key products and benefits of the Datacenter threat-centric solution? (Choose three.)

The correct answer is C. Automated policy enforcement with ASAv D. Software-defines segmentation through TrustSec E. Deep visibility and data analytics through Stealthwatch. Cisco's Datacenter threat-centric solution is built around three pillars: policy enforcement (ASAv), segmentation (TrustSec), and visibility (Stealthwatch). ASAv delivers automated policy enforcement by applying firewall rules dynamically in virtualized datacenter environments…

Cisco Security Portfolio Overview

Question

Which are three key products and benefits of the Datacenter threat-centric solution? (Choose three.)

Options

  • APredictive intelligence through Umbrella and Talos
  • BProactive packet inspection through Stealthwatch
  • CAutomated policy enforcement with ASAv
  • DSoftware-defines segmentation through TrustSec
  • EDeep visibility and data analytics through Stealthwatch
  • FIdentity-based policy management through Meraki

How the community answered

(44 responses)
  • B
    7% (3)
  • C
    91% (40)
  • F
    2% (1)

Explanation

Cisco's Datacenter threat-centric solution is built around three pillars: policy enforcement (ASAv), segmentation (TrustSec), and visibility (Stealthwatch). ASAv delivers automated policy enforcement by applying firewall rules dynamically in virtualized datacenter environments. TrustSec enables software-defined segmentation by tagging traffic with Security Group Tags (SGTs), isolating workloads without relying on physical network topology. Stealthwatch provides deep visibility and behavioral analytics by monitoring NetFlow data to detect anomalies and threats inside the datacenter.

Why the distractors are wrong:

  • A is wrong because Umbrella and Talos are associated with the Internet Edge/Cloud threat-centric solution, not the Datacenter solution.
  • B is wrong because Stealthwatch performs flow-based analysis, not packet inspection - that's the job of Firepower/ASA.
  • F is wrong because Meraki is a branch/WAN platform, and identity-based policy in the datacenter context belongs to ISE, not Meraki.

Memory tip: Think of the datacenter trio as "Enforce → Segment → See" - ASAv enforces, TrustSec segments, Stealthwatch sees. If an answer pairs a product with the wrong function (Stealthwatch + packet inspection) or puts a non-datacenter product in (Umbrella, Meraki), it's a distractor.

Topics

#Datacenter Security#ASAv#TrustSec#Stealthwatch

Community Discussion

No community discussion yet for this question.

Full 700-551 Practice