exam questions

Exam 350-701 All Questions

View all questions & answers for the 350-701 exam

Exam 350-701 topic 1 question 499 discussion

Actual exam question from Cisco's 350-701
Question #: 499
Topic #: 1
[All 350-701 Questions]

Which Cisco security solution provides patch management in the cloud?

  • A. Cisco Umbrella
  • B. Cisco ISE
  • C. Cisco CloudLock
  • D. Cisco Tetration
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Mocix
10 months, 1 week ago
Selected Answer: D
Analysis of Other Options: A. Cisco Umbrella: Cisco Umbrella is a cloud-delivered security service that provides DNS-layer security and internet-wide visibility to protect against malware, phishing, and command and control callbacks. It does not provide patch management capabilities. B. Cisco ISE (Identity Services Engine): Cisco ISE is a network access control and policy enforcement platform that provides visibility and control over users and devices on the network. It focuses on access control and identity management rather than patch management. C. Cisco CloudLock: Cisco CloudLock is a cloud-native CASB (Cloud Access Security Broker) and cloud cybersecurity platform that helps secure data, meet compliance requirements, and monitor and control cloud applications. It does not focus on patch management.
upvoted 1 times
...
iluvmicrosoft
1 year ago
the link from achille5, it states "baselines the installed software packages, package version, patch level, and more for every workload", the definition of patch management i believe is "Patch management is the process of applying firmware and software updates to improve functionality, close security vulnerabilities, and optimize performance." - the link does not say it applies firmware.. it states that it baselines.. - w that said.. im still confused as to what the right answer is
upvoted 1 times
...
fdl543
1 year, 9 months ago
Selected Answer: D
D is correct. Tetration = Cisco Secure Workload.
upvoted 2 times
...
achille5
2 years ago
Selected Answer: D
https://www.cisco.com/c/en/us/products/collateral/data-center-analytics/tetration-analytics/q-and-a-c67-737402.html
upvoted 4 times
DWizard
1 year, 9 months ago
This is the right answer. Umbrella and Cloudlock do not provide patch management, so the answer can only be ISE and Tetration (Secure Workload), the question is about patch management in the cloud, so it leaves only Tetration as the possible answer and you can confirm it with the link provided by achille5
upvoted 1 times
...
achille5
2 years ago
Software inventory and vulnerability detection: The Cisco Secure Workload platform baselines the installed software packages, package version, patch level, and more for every workload. The platform maintains an up-to-date CVE data feed from multiple sources, including NIST and OS vendor data packs, which contain the latest vulnerability and exposure information. Using this, Secure Workload checks whether the software packages have known information security vulnerabilities. When a vulnerability is detected, complete details—including the severity and impact score—can be found. You can then quickly find all the servers with the same version of the package installed for patching and planning purposes. Security operations can predefine policies with specific actions, such as quarantining a host when servers have packages with certain vulnerabilities.
upvoted 2 times
...
...
sull3y
2 years, 3 months ago
C. Cisco CloudLock is a security solution that provides patch management in the cloud. Cisco CloudLock is a cloud-based security solution that provides organizations with visibility and control over their cloud-based assets, such as SaaS apps, IaaS, and PaaS. It includes a feature called CloudLock Patch Management, which allows organizations to identify and remediate vulnerabilities in cloud-based assets, including software vulnerabilities, configuration issues, and missing patches. It also provides automated patching for cloud-based assets, which can help organizations to keep their cloud-based assets up-to-date and secure. In summary, Cisco CloudLock is a security solution that provides patch management in the cloud, it allows organizations to identify and remediate vulnerabilities in cloud-based assets, including software vulnerabilities, configuration issues, and missing patches, and also provides automated patching for cloud-based assets, which can help organizations to keep their cloud-based assets up-to-date and secure.
upvoted 2 times
Felice44
2 years ago
Can you post a link or source? I haven't found anything related to what you say
upvoted 1 times
...
sull3y
2 years, 3 months ago
Cisco CloudLock, on the other hand, is a cloud-based security solution that provides visibility and control over cloud-based assets, such as SaaS apps, IaaS, and PaaS. It provides a comprehensive set of security capabilities that can be used to protect cloud-based assets, including CloudLock Patch Management, CloudLock Identity and Access Management, CloudLock Data Loss Prevention, and CloudLock Cloud Access Security Broker (CASB) capabilities. CloudLock also includes a feature called Cloud Discovery, which allows organizations to identify and inventory all of their cloud-based assets.
upvoted 2 times
fdl543
1 year, 9 months ago
sull3y always putting misleading information. I noticed a cetain pattern in his/her behavior across the question comments that I have been reading....
upvoted 2 times
...
Dorr20
1 year, 11 months ago
There is not a single reference for "CloudLock Patch Management" in Google or in Cloudlock documentation. I have no idea where you've got that information.
upvoted 2 times
...
...
...
west33637
2 years, 3 months ago
Selected Answer: D
Im going with D on this one. ISE does not manage the cloud, Tetration (Secure Workloads) does. See link below: https://www.cisco.com/c/en/us/products/collateral/data-center-analytics/tetration-analytics/q-and-a-c67-737402.html The Cisco Secure Workload platform baselines the installed software packages, package version, patch level, and more for every workload. The platform maintains an up-to-date CVE data feed from multiple sources, including NIST and OS vendor data packs, which contain the latest vulnerability and exposure information. Using this, Secure Workload checks whether the software packages have known information security vulnerabilities. When a vulnerability is detected, complete details—including the severity and impact score—can be found. You can then quickly find all the servers with the same version of the package installed for patching and planning purposes.
upvoted 2 times
west33637
2 years, 3 months ago
switching my vote to C, based on Sull3y's information above. Cloudlock seems to have a more comprehensive patch management solution.
upvoted 1 times
MPoels
1 year, 1 month ago
Bad choice...
upvoted 1 times
...
...
...
amtf8888
2 years, 3 months ago
Selected Answer: B
i am not sure answwer is right, cloud lock can not do patch management on HOST I CHOOSE ISE,Answer B
upvoted 1 times
sull3y
2 years, 3 months ago
it is patch management in the cloud based assets
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago