Knowee
Questions
Features
Study Tools

Which type of data is used by Cisco Cognitive Intelligence to find malicious activity that has bypassed security controls, or entered through unmonitored channels, and is operating inside an enterprise network?transactionsessionalertstatisticalNavigation Bar

Question

Which type of data is used by Cisco Cognitive Intelligence to find malicious activity that has bypassed security controls, or entered through unmonitored channels, and is operating inside an enterprise network?transactionsessionalertstatisticalNavigation Bar

🧐 Not the exact question you are looking for?Go ask a question

Solution

Cisco Cognitive Intelligence uses NetFlow data to find malicious activity that has bypassed security controls, or entered through unmonitored channels, and is operating inside an enterprise network.

Here are the steps:

  1. NetFlow, a network protocol developed by Cisco, is used to collect and monitor network traffic. This data helps to understand where traffic is coming from, where it's going, and how much traffic is being generated.

  2. Cisco Cognitive Intelligence analyzes this NetFlow data to identify patterns and detect anomalies. This could include unusual data transfers or communication with suspicious IP addresses.

  3. If the system detects potential malicious activity, it will generate an alert. This could be an indication that a security control has been bypassed or that unmonitored channels are being used.

  4. The system also uses statistical data to enhance its detection capabilities. This could include analyzing trends over time or comparing activity against known malicious patterns.

  5. The navigation bar is a user interface element that allows users to navigate through the system and access different features. It does not directly contribute to the detection of malicious activity, but it helps users to interact with the system and respond to alerts.

This problem has been solved

Similar Questions

Cognitive Analytics receives web proxy log and NetFlow information from which Cisco Stealthwatch device?Stealthwatch Management ConsoleFlow CollectorUDP DirectorFlow Sensor

________ refers to the tools used to store, retrieve, and send information.Multiple ChoiceInternetIntranetInformation technologyVirtual networkingIdentity theft

Which of the following is NOT a common data source for Cybersecurity Analytics ? Network Traffic LogsEmployee Email addressServer access logsIntrusion Detection System Alerts

After receiving an alert about a suspicious login attempt, a security analyst can access their _____ to gather information about the alert.1 pointSIEM tool dashboardnetwork protocol analyzer (packet sniffer)internal infrastructureplaybook

Fill in the blank: _____ are used to retain, analyze, and search an organization's log data to provide security information and alerts in real-time.1 pointOperating systemsnetwork protocol analyzers (packet sniffers)SIEM toolsPlaybooks

1/1

Upgrade your grade with Knowee

Get personalized homework help. Review tough concepts in more detail, or go deeper into your topic by exploring other relevant questions.