Cisco 350-201 Exam - Topic 10 Question 90 Discussion
An engineer notices that every Sunday night, there is a two-hour period with a large load of network activity. Upon further investigation, the engineer finds that the activity is from locations around the globe outside the organization's service area. What are the next steps the engineer must take?
A) Assign the issue to the incident handling provider because no suspicious activity has been observed during business hours. and D) Treat it as a false positive, and accept the SIEM issue as valid to avoid alerts from triggering on weekends.
B) Review the SIEM and FirePower logs, block all traffic, and document the results of calling the call center.
C) Define the access points using StealthWatch or SIEM logs, understand services being offered during the hours in Question:, and cross-correlate other source events.
Kati
9 months agoHarris
9 months agoTalia
10 months agoReiko
10 months agoPaulina
10 months agoOra
10 months agoTy
11 months agoKerrie
11 months agoJohnson
11 months agoKatlyn
11 months agoBen
11 months agoMerlyn
11 months agoMuriel
11 months agoStephane
11 months agoVenita
11 months agoMozell
11 months agoPearline
1 year agoFrederick
1 year agoJutta
1 year agoFlorinda
1 year agoLina
1 year agoHerminia
1 year agoEttie
1 year agoJutta
1 year agoAlonso
1 year agoArlyne
1 year agoCandra
1 year agoKimberely
1 year agoSelma
1 year agoKeith
1 year agoEleonore
1 year agoNovella
1 year agoHildred
1 year agoIn
1 year agoBobbye
1 year agoRessie
1 year agoAmie
1 year agoLorean
1 year agoZana
1 year agoNobuko
1 year ago