Courseiva
hardMultiple SelectObjective-mapped

350-701 Practice Question: Which THREE are characteristics of Cisco…

Which THREE are characteristics of Cisco Stealthwatch?

⚠ Common exam trap

Cisco often tests the distinction between detection/visibility tools (Stealthwatch) and inline enforcement devices (NGFW/IPS), so the trap here is that candidates confuse Stealthwatch's behavioral analysis and flow-based monitoring with the packet-inspecting, blocking capabilities of a next-generation firewall or intrusion prevention system.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Can integrate with Cisco ISE for automated threat response

Cisco Stealthwatch can integrate with Cisco ISE (Identity Services Engine) via pxGrid or REST API to enable automated threat response. When Stealthwatch detects anomalous behavior, it can trigger ISE to enforce policy changes such as quarantining an endpoint or dynamically applying a security group access control list (SGACL), closing the loop between detection and remediation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Can integrate with Cisco ISE for automated threat response

    Why this is correct

    Integration allows ISE to enforce policies based on Stealthwatch alerts.

  • Provides behavioral analysis to detect threats

    Why this is correct

    It uses machine learning to establish baselines and detect anomalies.

  • Acts as a next-generation firewall

    Why it's wrong here

    Stealthwatch is not a firewall; it's a traffic analysis tool.

  • Uses NetFlow and IPFIX for network traffic visibility

    Why this is correct

    Stealthwatch collects flow data from network devices.

  • Functions as an intrusion prevention system (IPS)

    Why it's wrong here

    It does not perform inline prevention; it is a detection and analysis tool.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This 350-701 question is part of Courseiva's 978-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.