Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 350-701 Exam - Topic 4 Question 119 Discussion

[Security Concepts]An organization wants to implement a cloud-delivered and SaaS-based solution to provide visibility and threat detection across the AWS network. The solution must be deployed without software agents and rely on AWS VPC flow logs instead. Which solution meets these requirements?
A) Cisco Stealthwatch Cloud
B) Cisco Umbrella
C) NetFlow collectors
D) Cisco Cloudlock

Cisco 350-701 Exam - Topic 4 Question 119 Discussion

Actual exam question for Cisco's 350-701 exam
Question #: 119
Topic #: 4
[All 350-701 Questions]

[Security Concepts]

An organization wants to implement a cloud-delivered and SaaS-based solution to provide visibility and threat detection across the AWS network. The solution must be deployed without software agents and rely on AWS VPC flow logs instead. Which solution meets these requirements?

Show Suggested Answer Hide Answer
Suggested Answer: A

Cisco Stealthwatch Cloud is a cloud-delivered and SaaS-based solution that provides visibility and threat detection across the AWS network. It does not require any software agents to be installed on the AWS instances, and it relies on AWS VPC flow logs to collect network traffic metadata. Cisco Stealthwatch Cloud analyzes the flow logs using machine learning and behavioral modeling to detect anomalies and threats, such as data exfiltration, lateral movement, reconnaissance, and compromised instances. Cisco Stealthwatch Cloud also provides contextual information and actionable alerts to help users respond to incidents and remediate issues.

Cisco Umbrella is a cloud-delivered and SaaS-based solution that provides DNS-layer security and web filtering for internet traffic. It does not provide visibility and threat detection for internal AWS network traffic, and it requires software agents to be installed on the endpoints or network devices to enforce policies and redirect DNS requests.

NetFlow collectors are devices or software applications that collect and analyze NetFlow records, which are generated by network devices to capture information about IP traffic flows. NetFlow collectors can provide visibility and threat detection for network traffic, but they are not cloud-delivered or SaaS-based solutions. They also require NetFlow exporters to be configured on the network devices, which may not be supported by AWS.

Cisco Cloudlock is a cloud-delivered and SaaS-based solution that provides cloud security posture management (CSPM) and cloud access security broker (CASB) capabilities for cloud applications and environments. It does not provide visibility and threat detection for AWS network traffic, and it does not rely on AWS VPC flow logs. It focuses on protecting cloud data, users, and configurations from misconfigurations, compliance violations, and malicious activities.Reference:=

Cisco Stealthwatch Cloud for AWS

Cisco Umbrella

NetFlow

[Cisco Cloudlock]


Contribute your Thoughts:

0/2000 characters
Audry
4 months ago
D) Cisco Cloudlock seems less relevant for threat detection.
upvoted 0 times
...
Kimberlie
4 months ago
C) NetFlow collectors could work, but they might need more setup.
upvoted 0 times
...
Tawna
4 months ago
I’m leaning towards B) Cisco Umbrella. It offers great visibility too.
upvoted 0 times
...
Lauran
5 months ago
I think A) Cisco Stealthwatch Cloud is the best choice. It integrates well with AWS.
upvoted 0 times
...
Maryann
5 months ago
C) NetFlow collectors? Not quite the same as SaaS.
upvoted 0 times
...
Roselle
5 months ago
B) Cisco Umbrella is more for DNS security, not this.
upvoted 0 times
...
Eun
5 months ago
Wait, can it really work without agents?
upvoted 0 times
...
Cathrine
5 months ago
I agree, it’s designed for AWS flow logs.
upvoted 0 times
...
Daniel
5 months ago
A) Cisco Stealthwatch Cloud is the right choice!
upvoted 0 times
...
Sheron
6 months ago
Cisco Stealthwatch Cloud, no doubt. Unless you're a fan of wearing a blindfold while driving, that is.
upvoted 0 times
...
Dorinda
6 months ago
Cisco Stealthwatch Cloud all the way! Who needs software agents when you've got VPC flow logs, am I right?
upvoted 0 times
...
Dalene
6 months ago
Hmm, I'm torn between A and C. Both sound like they could work, but Cisco Stealthwatch Cloud might be the safer bet.
upvoted 0 times
...
Latosha
7 months ago
I'd go with option A. Cisco Stealthwatch Cloud checks all the boxes for this requirement.
upvoted 0 times
...
Farrah
7 months ago
Cisco Stealthwatch Cloud seems like the obvious choice here. No software agents and uses VPC flow logs - perfect fit!
upvoted 0 times
...
Marylyn
7 months ago
I don’t think NetFlow collectors are the right choice here since they usually require more setup. Cisco Cloudlock seems more about data security, not threat detection.
upvoted 0 times
...
Lavera
7 months ago
I’m leaning towards Cisco Stealthwatch Cloud, but I’m a bit confused about how it integrates with AWS without agents. I need to double-check that.
upvoted 0 times
...
Terrilyn
7 months ago
I feel like I've seen a question similar to this in practice exams, and I think Cisco Umbrella was more focused on DNS security rather than threat detection.
upvoted 0 times
...
Susana
7 months ago
I think I remember something about Cisco Stealthwatch Cloud being used for visibility in AWS environments, but I'm not entirely sure if it specifically uses VPC flow logs.
upvoted 0 times
...
Jamal
8 months ago
Hmm, I'm not too familiar with these specific products. I'll need to do a quick review of each one to understand the differences and how they match the requirements. Gotta make sure I pick the right answer here.
upvoted 0 times
...
Ryan
8 months ago
I've used Cisco Stealthwatch Cloud before, and I think that's the best solution here. It checks all the boxes - cloud-delivered, SaaS, and uses VPC flow logs without agents. Seems like the obvious choice to me.
upvoted 0 times
...
Marvel
8 months ago
I'm a bit confused by the options. Cisco Umbrella and Cloudlock don't seem to match the requirements. NetFlow collectors could work, but I'm not sure if they're SaaS-based. I'll have to review the details on each one.
upvoted 0 times
...
Carrol
8 months ago
Okay, let's see. The key things are that it needs to be cloud-delivered, SaaS-based, and use VPC flow logs without agents. I'm thinking Cisco Stealthwatch Cloud might be the best fit.
upvoted 0 times
...
Maile
8 months ago
Hmm, this seems like a tricky one. I'll need to think carefully about the requirements and match them to the options.
upvoted 0 times
Mozell
2 months ago
But what about Cisco Umbrella? It might also work for visibility.
upvoted 0 times
...
Arthur
2 months ago
Yeah, it fits the no-agent requirement perfectly.
upvoted 0 times
...
Eleni
4 months ago
I think Cisco Stealthwatch Cloud could be the right choice.
upvoted 0 times
...
...

Save Cancel