Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-745 Exam - Topic 1 Question 2 Discussion

After deploying a new API, the security team must identify the components of the application that are exposed to the internet and whether there are application authentication risks. Which technology must be deployed to discover the applications services and monitor for authentication issues?
B) API trace analysis
A) Cloud Security Posture Management
C) secret scanning
D) Cloud Workload Protection

Cisco 300-745 Exam - Topic 1 Question 2 Discussion

Actual exam question for Cisco's 300-745 exam
Question #: 2
Topic #: 1
[All 300-745 Questions]

After deploying a new API, the security team must identify the components of the application that are exposed to the internet and whether there are application authentication risks. Which technology must be deployed to discover the applications services and monitor for authentication issues?

Show Suggested Answer Hide Answer
Suggested Answer: B

Securing APIs requires visibility into the 'runtime' behavior of the application. API trace analysis (often part of an API Security solution like Cisco Panoptica) is the technology used to automatically discover API endpoints and analyze the traffic flowing through them. This process identifies 'shadow APIs' (undocumented endpoints) that are exposed to the internet and inspects the headers and payloads for authentication risks, such as missing tokens or broken object-level authorization (BOLA).

By monitoring actual traffic traces, the security team can confirm if the API is following the intended security design or if it is leaking sensitive data due to poor authentication implementation. Cloud Security Posture Management (CSPM) (Option A) focuses on the configuration of the cloud infrastructure (like an open S3 bucket) rather than the internal logic of an API's authentication. Secret scanning (Option C) is a 'shift-left' technique used to find hardcoded passwords in source code during the build phase, not for monitoring live traffic. Cloud Workload Protection (CWPP) (Option D) focuses on protecting the underlying host or container from malware and exploits. Only API trace analysis provides the specific visibility into service discovery and application-layer authentication health required in the Cisco SDSI v1.0 objectives for modern DevSecOps environments.


Contribute your Thoughts:

0/2000 characters
Dianne
3 days ago
D) Cloud Workload Protection is good for overall security, but not specific enough for this task.
upvoted 0 times
...
Whitney
8 days ago
C) Secret scanning is important, but it doesn’t focus on authentication risks.
upvoted 0 times
...
Sherita
13 days ago
A) Cloud Security Posture Management could work too, but it’s broader.
upvoted 0 times
...
Lino
19 days ago
I think B) API trace analysis is the best choice. It directly monitors API calls.
upvoted 0 times
...
Malcom
24 days ago
D) Cloud Workload Protection is good, but it feels too broad for this specific issue.
upvoted 0 times
...
Carolynn
29 days ago
C) Secret scanning is important, but it doesn't address authentication risks directly.
upvoted 0 times
...
Elfrieda
1 month ago
I agree, but A) Cloud Security Posture Management could also help identify exposed components.
upvoted 0 times
...
Ma
1 month ago
I think B) API trace analysis is the best choice. It directly monitors API calls.
upvoted 0 times
...
Lorriane
1 month ago
D) Cloud Workload Protection is good, but it’s more about overall security than just APIs.
upvoted 0 times
...
Dorthy
2 months ago
C) secret scanning is important, but it doesn't focus on authentication risks.
upvoted 0 times
...
Gussie
2 months ago
I agree, but A) Cloud Security Posture Management could also help identify exposed components.
upvoted 0 times
...
Jolanda
2 months ago
I think B) API trace analysis is the best choice. It directly monitors API calls.
upvoted 0 times
...
Erick
2 months ago
I’m surprised this isn’t more straightforward; it feels like a mix of options!
upvoted 0 times
...
Eveline
2 months ago
I agree with Jerry, API trace analysis is crucial here.
upvoted 0 times
...
Delmy
4 months ago
Wait, secret scanning? Isn’t that more for code than APIs?
upvoted 0 times
...
Lisandra
4 months ago
I think A) Cloud Security Posture Management is more comprehensive.
upvoted 0 times
...
Jerry
4 months ago
Definitely B) API trace analysis for monitoring.
upvoted 0 times
...
Georgeanna
4 months ago
Huh, I thought D) Cloud Workload Protection would cover this too.
upvoted 0 times
...
Tandra
5 months ago
I agree with Earleen, B is the way to go!
upvoted 0 times
...
Royal
5 months ago
Wait, secret scanning? Isn't that more for code vulnerabilities?
upvoted 0 times
...
Lanie
5 months ago
I think A) Cloud Security Posture Management is also crucial here.
upvoted 0 times
...
Earleen
5 months ago
Definitely B) API trace analysis for monitoring those authentication issues.
upvoted 0 times
...
Georgeanna
5 months ago
Cloud Workload Protection seems like it could help, but I don't recall it being specifically for authentication issues.
upvoted 0 times
...
Rachael
5 months ago
I feel like secret scanning is more about finding exposed credentials rather than monitoring services.
upvoted 0 times
...
Erick
6 months ago
I'm not entirely sure, but I remember something about Cloud Security Posture Management being used for visibility.
upvoted 0 times
...
Sabra
6 months ago
I think it's related to monitoring, so maybe API trace analysis? That sounds familiar from our practice questions.
upvoted 0 times
...

Save Cancel