ExamGecko
Question list
Search
Search

Question 257 - 350-701 discussion

Report
Export

An engineer needs a cloud solution that will monitor traffic, create incidents based on events, and integrate with other cloud solutions via an API. Which solution should be used to accomplish this goal?

A.

SIEM

Answers
A.

SIEM

B.

CASB

Answers
B.

CASB

C.

Adaptive MFA

Answers
C.

Adaptive MFA

D.

Cisco Cloudlock

Answers
D.

Cisco Cloudlock

Suggested answer: D

Explanation:

+ Cisco Cloudlock continuously monitors cloud environments with a cloud Data Loss Prevention (DLP) engine to identify sensitive information stored in cloud environments in violation of policy.

+ Cloudlock is API-based.

+ Incidents are a key resource in the Cisco Cloudlock application. They are triggered by the Cloudlock policy engine when a policy detection criteria result in a match in an object (document, field, folder, post, or file).

Reference: https://docs.umbrella.com/cloudlock-documentation/docs/endpointsNote:

+ Security information and event management (SIEM) platforms collect log and event data from security systems, networks and computers, and turn it into actionable security insights.

+ An incident is a record of the triggering of an alerting policy. Cloud Monitoring opens an incident when a condition of an alerting policy has been met.

asked 10/10/2024
Sumit Sengupta
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first