exam questions

Exam 350-701 All Questions

View all questions & answers for the 350-701 exam

Exam 350-701 topic 1 question 90 discussion

Actual exam question from Cisco's 350-701
Question #: 90
Topic #: 1
[All 350-701 Questions]

An engineer needs behavioral analysis to detect malicious activity on the hosts, and is configuring the organization's public cloud to send telemetry using the cloud provider's mechanisms to a security device. Which mechanism should the engineer configure to accomplish this goal?

  • A. sFlow
  • B. NetFlow
  • C. mirror port
  • D. VPC flow logs
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
acc2326
Highly Voted 3 years, 11 months ago
correct answer is D - VPC flow logs
upvoted 9 times
...
jaciro11
Highly Voted 3 years, 5 months ago
Its D I totally remember when I configure the first time the Stealthwatch Cloud
upvoted 9 times
...
Nonono2
Most Recent 10 months ago
Selected Answer: D
VPC flow logs
upvoted 1 times
...
Marshpillowz
1 year, 1 month ago
Selected Answer: D
D is correct
upvoted 1 times
...
psuoh
2 years, 3 months ago
A, B, C are for data networks containing switches and routers VPC slow log is meant for cloud based network like AWS. Now, Secure Cloud Analytics (formerly Stealthwatch Cloud) can automatically retrieve VPC Flow Logs as a primary or supplementary data source for entity modeling. This means you can now monitor network activity in a cloud environment and increase your security.
upvoted 2 times
...
Rhoads
2 years, 3 months ago
Selected Answer: D
Using the cloud provider..
upvoted 2 times
...
sis_net_sec
2 years, 9 months ago
Selected Answer: D
Stealthwatch Cloud can be deployed without software agents, relying on the native AWS Virtual Private Cloud (VPC) flow logs. https://aws.amazon.com/marketplace/pp/prodview-woiawecmdlezq
upvoted 3 times
...
semi1750
3 years ago
D - VPC flow logs is answer The question asks "public cloud" and cisco made the following explanation. Cisco Telemetry Broker The Cisco Telemetry Broker is capable of ingesting network telemetry from a variety of telemetry sources, transforming their data formats, and then forwarding that telemetry to one or multiple destinations. For example, it can ingest any of the following: ● On-premises network telemetry, including NetFlow, SYSLOG, and IPFIX ● Cloud-based telemetry sources, such as AWS VPC flow logs and Azure NSG flow logs And it can forward that telemetry to any or all of the following example destinations: ● Analytics platforms, such as Hadoop ● Network management and automation platforms, such as Cisco DNA Center ● Security Information and Event Management (SIEM) platforms ● Storage/smart capture, such as Cisco Security Analytics and Logging (On-premises) https://www.cisco.com/c/en/us/products/collateral/security/stealthwatch/datasheet-c78-739398.html
upvoted 3 times
...
brownbear505
3 years, 2 months ago
Selected Answer: D
Specifically, AWS VPC Flow Logs contain the following information: ●      Which IP entities are communicating inside and outside the VPC ●      Which protocols (such as TCP and UDP) are being used ●      How much traffic is sent and received by each entity ●      Whether the flow was allowed or blocked by the security policy
upvoted 3 times
psuoh
2 years, 3 months ago
https://www.cisco.com/c/en/us/products/collateral/security/stealthwatch-cloud/at-a-glance-c45-739851.html
upvoted 1 times
...
...
Minion2021
3 years, 2 months ago
Correct answer is D
upvoted 2 times
...
dr4gn00t
3 years, 3 months ago
This is a tricky question. VPC is valid option only for AWS (Azure and Google uses different terms), and AWS doesn't send telemetry to Stealthwatch. Stealthwatch fetch logs from AWS via API. I think B is therefore most valid answer.
upvoted 4 times
...
neta1o
3 years, 3 months ago
Looks like this solution supports Azure and AWS. Based on the docs for Azure setup it doesn't look like they refer to the logs as VPC Flow Logs (AWS). So based on that I'd stick with B. https://www.cisco.com/c/en/us/support/security/stealthwatch-cloud/products-installation-guides-list.html#pcm
upvoted 3 times
...
VI_Vershinin
3 years, 9 months ago
It's B From the book SCOR 350-701: Stealthwatch Cloud is a Software as a Service (SaaS) cloud solution. You can use Stealthwatch Cloud to monitor many different public cloud environments, such as Amazon’s AWS, Google Cloud Platform, and Microsoft Azure. All of these cloud providers support their own implementation of NetFlow: ■■ In Amazon AWS, the equivalent of NetFlow is called VPC Flow Logs. You can obtain detailed information about VPC Flow Logs in AWS at https://docs.aws.amazon.com/ vpc/latest/userguide/flow-logs.html. ■■ Google Cloud Platform also supports VPC Flow Logs (or Google-branded GPC Flow Logs). You can obtain detailed information about VPC Flow Logs in Google Cloud Platform at https://cloud.google.com/vpc/docs/using-flow-logs. ■■ In Microsoft’s Azure, traffic flows are collected in Network Security Group (NSG) flow logs. NSG flow logs are a feature of Network Watcher. You can obtain additional information about Azure’s NSG flow logs and Network Watcher at https://docs.microsoft. com/en-us/azure/network-watcher/network-watcher-nsg-flow-logging-overview
upvoted 4 times
...
Dinges
3 years, 10 months ago
Its D https://aws.amazon.com/marketplace/pp/prodview-woiawecmdlezq
upvoted 3 times
...
SirFrates24
3 years, 10 months ago
Not seeing anything related to PUBLIC CLOUD and vpc
upvoted 1 times
Stardec
3 years, 6 months ago
https://www.cisco.com/c/en/us/products/collateral/security/stealthwatch-cloud/at-a-glance-c45-739850.html
upvoted 1 times
...
...
yenp
3 years, 10 months ago
correct answer is b : In AWS environments, Cisco Stealthwatch Cloud can be deployed without software agents, relying on the native AWS Virtual Private Cloud (VPC) flow logs. Deployment can be accomplished in minutes by simply giving Cisco Stealthwatch Cloud read-only access to these VPC flow logs. In addition to VPC flows logs, other AWS telemetry data can also be used. GCP also uses VPC flow logs for rapid deployment and integration. Currently for Microsoft Azure environments, Cisco Stealthwatch Cloud relies first on a Linux-based software appliance, called the Observable Networks Appliance (ONA), and second on a third-party host-based NetFlow exporter such as Ziften or FlowTraq.
upvoted 2 times
Maleck
3 years, 10 months ago
You mean Correct answer is D from your explanation
upvoted 3 times
...
...
wfexco
3 years, 11 months ago
Answer is D - Stealthwatch Cloud can be deployed without software agents, relying on the native AWS Virtual Private Cloud (VPC) flow logs
upvoted 4 times
statikd
3 years, 10 months ago
How is it VPC flow logs when this question is an organization's public cloud, not a private cloud?
upvoted 1 times
itisfakemaillol
3 years, 10 months ago
VPC flow logs are the feature of the public clouds, like AWS
upvoted 2 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago