Cisco CCNP Security Core (SCOR) 350-701Visibility and EnforcementHard

A security operations center (SOC) analyst is investigating a potential data exfiltration event. Network flow data (NetFlow) shows unusually large outbound traffic from an internal server to an unknown external IP address, but the destination port is frequently changing. Traditional firewall logs only show permitted 'any' rules for this server's outbound traffic. Which Cisco visibility technology would be most effective in identifying the specific application or process generating this anomalous traffic?

  1. ACisco Identity Services Engine (ISE) with endpoint posture assessment.
  2. BCisco Firepower Management Center (FMC) with deep packet inspection (DPI).
  3. CCisco Umbrella with domain-level logging.
  4. DCisco Secure Network Analytics (Stealthwatch) with application visibility.
Show answer & explanation

Correct answer: D. Cisco Secure Network Analytics (Stealthwatch) with application visibility.

Cisco Secure Network Analytics (Stealthwatch) excels at analyzing NetFlow data for behavioral anomalies and can often identify the specific application or process behind traffic flows, even with changing ports, by leveraging its deep understanding of flow telemetry and application mapping. FMC's DPI is effective but might not be deployed everywhere and is more signature-based.

Why the other options are wrong

  • A. ISE focuses on user and device identity and access control, not deep analysis of application-level traffic anomalies.
  • B. FMC with DPI is good for signature-based detection and application identification but relies on traffic passing through an FTD sensor, and Stealthwatch offers broader network-wide visibility for anomalous flows.
  • C. Umbrella provides DNS-layer security and logging, which would show domain access but not the specific application or process on the internal server generating the traffic.

Cisco Secure Network Analytics (Stealthwatch)

A network visibility and security analytics solution that uses NetFlow/IPFIX data to provide comprehensive awareness of network activity, detect advanced threats, and respond to incidents. It builds a baseline of normal behavior to identify anomalies.

  • Analyzes network flow data (NetFlow, IPFIX).
  • Detects anomalous behavior, insider threats, data exfiltration.
  • Provides application visibility and identifies network conversations.
  • Integrates with other security tools for automated response.

Memory trick: For tricky traffic, Stealthwatch uncovers the hidden app's path.

More Visibility and Enforcement questions