exam questions

Exam 300-710 All Questions

View all questions & answers for the 300-710 exam

Exam 300-710 topic 1 question 206 discussion

Actual exam question from Cisco's 300-710
Question #: 206
Topic #: 1
[All 300-710 Questions]

Upon detecting a flagrant threat on an endpoint, which two technologies instruct Cisco Identity Services Engine to contain the infected endpoint either manually or automatically? (Choose two.)

  • A. Cisco Stealthwatch
  • B. Cisco ASA 5500 Series
  • C. Cisco FMC
  • D. Cisco ASR 7200 Series
  • E. Cisco AMP
Show Suggested Answer Hide Answer
Suggested Answer: CE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
c946f3e
Highly Voted 1 year, 4 months ago
AE : Both Cisco STEALTHWATCH and AMP can instruct ISE to take appropriate actions base on the endpoint compliance status
upvoted 5 times
...
rbrain
Most Recent 1 month ago
Selected Answer: AC
Must be A and C Based on the feature RTC which AMP for endpoints does not seem to have
upvoted 3 times
...
houhou12322
4 months, 1 week ago
I think A, C and E are correct (FMC with correlation policy and remediation)
upvoted 2 times
...
Doris8000
6 months, 2 weeks ago
I meant the correct answer is C-E
upvoted 1 times
...
z6st2a1jv
1 year, 2 months ago
Selected Answer: AE
Its not C, becque FMC does not instruct ISE. Its the other way around: FMC can enforce an organization’s security policy based on ISE session attribute information available through pxGrid.
upvoted 2 times
...
SegaMasterSystemAdmin
1 year, 7 months ago
Selected Answer: AC
Looks like A and C https://www.cisco.com/c/m/en_uk/products/security/identity-services-engine/use-case-threat-containment.html#~onboard
upvoted 1 times
...
Initial14
1 year, 9 months ago
Selected Answer: AE
A and E are correct !!! If you read FMC white paper you know that FMC can instruct ISE to shutdown, Quarantine host. And this can also be done with stealthwatch: https://cisco.bravais.com/s/O3aQkU0OU6fNYhUrsuES If you think, why would AMP do that, when AMP can already block threat on the host itself ?
upvoted 3 times
...
matan24
1 year, 9 months ago
Stealthwatch and FirePOWER are both on-prem network solutions that have integration with ISE. AMP, as a cloud solution, doesn't have an integration with ISE, as far as I know of. I'm going with A & C
upvoted 2 times
gwb
9 months, 4 weeks ago
FMC through pxGrid integration with ISE - yes possible. Stealwatch is also possible. So my answer is A and C. Cisco Stealthwatch has the capability to take automated actions to block threats or suspicious behavior on endpoints. Here are the relevant features: Adaptive Network Control (ANC): When integrated with Cisco Identity Services Engine (ISE), Stealthwatch can trigger ANC policy changes. These changes modify or limit an endpoint’s level of access to the network. In other words, if Stealthwatch detects a threat, it can automatically quarantine the compromised endpoint by adjusting network access through authorization policies or Security Group Tags (SGT)
upvoted 1 times
...
Initial14
1 year, 9 months ago
https://community.cisco.com/t5/network-access-control/cisco-ise-amp-for-endpoints-integration/td-p/4273949
upvoted 1 times
...
...
Joe_Blue
1 year, 10 months ago
Cisco Stealthwatch is not a technology that instructs Cisco Identity Services Engine (ISE) to contain the infected endpoint either manually or automatically. Cisco Stealthwatch is a network visibility and security analytics platform that uses NetFlow, telemetry, and machine learning to detect threats across the network, including advanced malware and insider threats. It provides network behavior analysis (NBA) to identify anomalies, threat hunting to investigate incidents, and network segmentation to limit the attack surface.
upvoted 1 times
...
tanri04
1 year, 10 months ago
he two technologies that can instruct Cisco Identity Services Engine to contain the infected endpoint either manually or automatically are: Cisco Stealthwatch Cisco AMP Both Cisco Stealthwatch and Cisco AMP have integration with Cisco Identity Services Engine to automate the quarantine or isolation of the endpoint upon detecting a threat.
upvoted 1 times
...
Joe_Blue
1 year, 10 months ago
Selected Answer: CE
The two technologies that can instruct Cisco Identity Services Engine (ISE) to contain an infected endpoint, either manually or automatically, upon detecting a flagrant threat on the endpoint are: C. Cisco FMC E. Cisco AMP for Endpoints
upvoted 4 times
...
uedemdog
1 year, 10 months ago
Selected Answer: CE
RTC w/ FMC & ISE is the ability for the FMC to quarantine end points through ISE. So, when the FMC sees some indicators of compromise, certain Snort IPS signatures are fired, or malware is discovered through AMP, the FMC can trigger actions to occur through ISE. ISE, in turn, can determine what to do when that trigger occurs. ISE could kick the user off the network or change the context of the user and endpoint so that different actions are taken within the network infrastructure.
upvoted 3 times
...
Baumb
1 year, 11 months ago
Selected Answer: AC
E cannot be correct here if the answer to question 212 is correct (Who tells ISE to contain the endpoint? Correct answer at 212 is FMC) So I go with A and C here
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago