DevNet Associate (DEVASC) v1.0Cisco Platforms and DevelopmentMedium

A network security engineer needs to integrate Cisco FSO (Full-Stack Observability) with a custom security orchestration platform. The platform requires the ability to programmatically retrieve a list of all vulnerabilities detected across the monitored applications and infrastructure, including their severity and affected entities. Which type of Cisco FSO API would be most appropriate for this requirement?

  1. AEvent Egress API
  2. BMetric Ingestion API
  3. CConfiguration API
  4. DQuery APIs
Show answer & explanation

Correct answer: D. Query APIs

Cisco FSO's Query APIs are designed for retrieving specific data points, such as vulnerabilities, metrics, and logs, from the observability platform. This allows for programmatic access to the detected security posture and affected entities.

Why the other options are wrong

  • A. Event Egress APIs (often webhooks) push data out based on events, but a 'list of all vulnerabilities' implies a pull-based query.
  • B. Metric Ingestion APIs are for sending data INTO FSO, not for retrieving data OUT of it.
  • C. Configuration APIs are used for setting up and managing FSO components, not for retrieving detected vulnerabilities.

Cisco FSO Query APIs

Cisco Full-Stack Observability (FSO) Query APIs provide programmatic access to retrieve observed data, including metrics, logs, traces, and security vulnerabilities, from the FSO platform.

  • Used for data retrieval and reporting.
  • Supports various query languages or formats depending on the FSO module.
  • Enables integration with external analytics and security platforms.

Memory trick: FSO APIs handle data 'in, out, and around'.

More Cisco Platforms and Development questions