700-765 · Question #74
Which feature of CTA can separate statistically normal traffic form anomalous traffic?
The correct answer is C. Anomaly detection. Cisco CTA (Cognitive Threat Analytics) uses anomaly detection to establish a behavioral baseline and identify traffic that statistically deviates from that normal pattern.
Question
Which feature of CTA can separate statistically normal traffic form anomalous traffic?
Options
- AURL filtering
- BTrust modeling
- CAnomaly detection
- DEvent classification
How the community answered
(28 responses)- A4% (1)
- B4% (1)
- C93% (26)
Why each option
Cisco CTA (Cognitive Threat Analytics) uses anomaly detection to establish a behavioral baseline and identify traffic that statistically deviates from that normal pattern.
URL filtering blocks access to known malicious or categorized URLs but does not statistically model or separate normal traffic patterns from anomalous ones.
Trust modeling in CTA assesses the trustworthiness of endpoints or users but is not the mechanism responsible for separating normal traffic from statistically anomalous traffic.
Anomaly detection in CTA works by building statistical models of normal user and network behavior, then flagging traffic that deviates significantly from those baselines. This allows CTA to surface threats such as command-and-control communications or data exfiltration that blend into normal-looking traffic. It is the core mechanism that distinguishes legitimate traffic from potentially malicious activity without relying solely on known signatures.
Event classification categorizes detected events by type or severity after they have been identified, rather than performing the statistical separation of normal versus anomalous traffic.
Concept tested: CTA anomaly detection and behavioral baselining
Source: https://www.cisco.com/c/en/us/products/security/cognitive-threat-analytics/index.html
Topics
Community Discussion
No community discussion yet for this question.