QuestionQ37

Incident Response Techniques

A network host is compromised by malware after an attacker uses it to request files and relay traffic to bots. The attack was not detected and caused a significant loss. The organization wants to prevent a recurrence and needs a security solution that generates alerts when command-and-control communication from an infected device is detected. Which network security solution should be recommended?

  • A Cisco Secure Firewall ASA
  • B Cisco Secure Firewall Threat Defense (Firepower)
  • C Cisco Secure Email Gateway (ESA)
  • D Cisco Secure Web Appliance (WSA)
Explanation

Cisco Secure Firewall Threat Defense (Firepower) provides network threat detection and intrusion inspection capabilities that identify malicious traffic, including communications between compromised clients and command-and-control servers, and can generate security events and alerts.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!