Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 350-201 Exam - Topic 10 Question 90 Discussion

An engineer notices that every Sunday night, there is a two-hour period with a large load of network activity. Upon further investigation, the engineer finds that the activity is from locations around the globe outside the organization's service area. What are the next steps the engineer must take?
A) Assign the issue to the incident handling provider because no suspicious activity has been observed during business hours. and D) Treat it as a false positive, and accept the SIEM issue as valid to avoid alerts from triggering on weekends.
B) Review the SIEM and FirePower logs, block all traffic, and document the results of calling the call center.
C) Define the access points using StealthWatch or SIEM logs, understand services being offered during the hours in Question:, and cross-correlate other source events.

Cisco 350-201 Exam - Topic 10 Question 90 Discussion

Actual exam question for Cisco's 350-201 exam
Question #: 90
Topic #: 10
[All 350-201 Questions]

An engineer notices that every Sunday night, there is a two-hour period with a large load of network activity. Upon further investigation, the engineer finds that the activity is from locations around the globe outside the organization's service are

a. What are the next steps the engineer must take?

Show Suggested Answer Hide Answer
Suggested Answer: A, D

Contribute your Thoughts:

0/2000 characters
Kati
9 months ago
Cross-correlating events is a smart move!
upvoted 0 times
...
Harris
9 months ago
Wait, why would they treat it as a false positive? That seems risky.
upvoted 0 times
...
Talia
10 months ago
Definitely need to review those logs first!
upvoted 0 times
...
Reiko
10 months ago
I think blocking all traffic is too extreme.
upvoted 0 times
...
Paulina
10 months ago
Sounds like a classic case of unauthorized access!
upvoted 0 times
...
Ora
10 months ago
I think blocking all traffic might be too extreme. Option A feels like it could lead to missing something important, but I can't quite remember the details.
upvoted 0 times
...
Ty
11 months ago
I'm a bit confused about whether to treat this as a false positive or not. Option D seems risky, but I can see why someone might consider it.
upvoted 0 times
...
Kerrie
11 months ago
I feel like we had a similar practice question where we had to analyze network traffic. I think option C makes sense because understanding the access points is crucial.
upvoted 0 times
...
Johnson
11 months ago
I remember we discussed the importance of reviewing logs in our last class. I think option B might be the right approach, but I'm not entirely sure.
upvoted 0 times
...
Katlyn
11 months ago
I'm a bit confused by this question. Option D seems like the easiest solution, but I'm not sure if that's the right call. I'll need to think this through carefully before making a decision.
upvoted 0 times
...
Ben
11 months ago
Okay, I've got a plan. I'll start by reviewing the SIEM and FirePower logs to get a better understanding of the network activity. Then I'll cross-correlate that with other sources to try and identify the access points and services being offered during those hours.
upvoted 0 times
...
Merlyn
11 months ago
Hmm, the question is a bit vague. I'm not sure which option would be the best approach here. I'll need to do some more research to figure this out.
upvoted 0 times
...
Muriel
11 months ago
This seems like a tricky one. I'll need to carefully review the options and think through the potential next steps.
upvoted 0 times
...
Stephane
11 months ago
This seems straightforward to me. Option C is clearly the best approach - we need to define the access points, understand the services, and cross-correlate the events to get to the bottom of this.
upvoted 0 times
...
Venita
11 months ago
Generating options is a good strategy here. Once I have a clear understanding of the problem, I can start brainstorming different ways to address the issue.
upvoted 0 times
...
Mozell
11 months ago
Hmm, this is a tricky one. I'm not entirely sure about the difference between a SAP and other QoS-related terms. I'll need to think this through step-by-step.
upvoted 0 times
...
Pearline
1 year ago
Option B is a bit extreme, like using a sledgehammer to crack a nut. The engineer should definitely dig deeper and get a clear understanding of what's going on before taking drastic action.
upvoted 0 times
Frederick
1 year ago
Option B is a bit extreme, like using a sledgehammer to crack a nut. The engineer should definitely dig deeper and get a clear understanding of what's going on before taking drastic action.
upvoted 0 times
...
Jutta
1 year ago
C) Define the access points using StealthWatch or SIEM logs, understand services being offered during the hours in Question:, and cross-correlate other source events.
upvoted 0 times
...
Florinda
1 year ago
Option B is a bit extreme, like using a sledgehammer to crack a nut. The engineer should definitely dig deeper and get a clear understanding of what's going on before taking drastic action.
upvoted 0 times
...
Lina
1 year ago
C) Define the access points using StealthWatch or SIEM logs, understand services being offered during the hours in Question:, and cross-correlate other source events.
upvoted 0 times
...
Herminia
1 year ago
A) Assign the issue to the incident handling provider because no suspicious activity has been observed during business hours.
upvoted 0 times
...
Ettie
1 year ago
A) Assign the issue to the incident handling provider because no suspicious activity has been observed during business hours.
upvoted 0 times
...
...
Jutta
1 year ago
Calling the incident handling provider? That's like calling the plumber to fix your computer. I think the engineer should use their investigative skills and get to the bottom of this.
upvoted 0 times
...
Alonso
1 year ago
Accepting this as a false positive is a terrible idea! That's like ignoring a fire alarm just because it's the weekend. Who knows what kind of havoc could be happening on the network.
upvoted 0 times
Arlyne
1 year ago
User 4: We should definitely define the access points and understand the services being offered during that time.
upvoted 0 times
...
Candra
1 year ago
User 3: Let's review the SIEM and FirePower logs to see what's going on.
upvoted 0 times
...
Kimberely
1 year ago
User 2: I agree, we can't just ignore unusual network activity.
upvoted 0 times
...
Selma
1 year ago
User 1: We need to take this seriously and investigate further.
upvoted 0 times
...
...
Keith
1 year ago
Option C seems like the most thorough approach. Defining the access points and understanding the services being offered during those hours will help pinpoint the root cause.
upvoted 0 times
Eleonore
1 year ago
User 2: I agree, but we should also define the access points using StealthWatch or SIEM logs to understand the services being offered during that time.
upvoted 0 times
...
Novella
1 year ago
User 1: I think we should review the SIEM and FirePower logs to block all traffic and document the results.
upvoted 0 times
...
...
Hildred
1 year ago
I believe defining the access points using StealthWatch or SIEM logs is crucial to understand the services being offered during that time.
upvoted 0 times
...
In
1 year ago
I agree with Nobuko. Blocking all traffic and documenting the results is a good next step.
upvoted 0 times
...
Bobbye
1 year ago
The engineer should definitely investigate this further. Blocking all traffic without understanding the issue could disrupt legitimate business operations.
upvoted 0 times
Ressie
1 year ago
A) Assign the issue to the incident handling provider because no suspicious activity has been observed during business hours.
upvoted 0 times
...
Amie
1 year ago
The engineer should definitely investigate this further. Blocking all traffic without understanding the issue could disrupt legitimate business operations.
upvoted 0 times
...
Lorean
1 year ago
B) Review the SIEM and FirePower logs, block all traffic, and document the results of calling the call center.
upvoted 0 times
...
Zana
1 year ago
C) Define the access points using StealthWatch or SIEM logs, understand services being offered during the hours in Question:, and cross-correlate other source events.
upvoted 0 times
...
...
Nobuko
1 year ago
I think the engineer should review the SIEM and FirePower logs.
upvoted 0 times
...

Save Cancel