easyMultiple Choice
200-201 Practice Question: Which Cisco tool provides network-wide visibility…
Which Cisco tool provides network-wide visibility and can detect anomalies using NetFlow and behavioral analysis?
⚠ Common exam trap
Watch out — candidates often confuse a device that generates NetFlow data (like a Catalyst switch) with a tool that analyzes NetFlow data for security anomalies, leading them to select the switch instead of the dedicated analytics platform.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cisco Secure Network Analytics (Stealthwatch)
Cisco Secure Network Analytics (formerly Stealthwatch) is the correct answer because it is a dedicated network visibility and security analytics platform that leverages NetFlow, IPFIX, and other telemetry sources to perform behavioral analysis and detect anomalies across the entire network. Unlike a firewall or switch, its primary function is to ingest flow data and apply machine learning models to identify threats such as lateral movement, data exfiltration, and command-and-control traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cisco Firepower Threat Defense (FTD)
Why it's wrong here
FTD is an inline next-generation firewall performing intrusion prevention and malware inspection on traffic crossing it, not NetFlow-based behavioural analytics across the whole network. It is tempting because FTD does detect threats, but its telemetry is flow-agnostic; Stealthwatch is the tool that ingests NetFlow for anomaly detection.
- ✗
Cisco Catalyst 9300 Switch
Why it's wrong here
A Catalyst 9300 is an access-layer switch that forwards traffic and can export NetFlow records, but it hosts no behavioural analytics engine to correlate them network-wide. It is tempting because switches are the NetFlow sources Stealthwatch consumes, yet the anomaly detection itself runs on a dedicated collector, not the switch.
- ✗
Cisco Identity Services Engine (ISE)
Why it's wrong here
ISE enforces identity-based network access and profiling through 802.1X and RADIUS, so it governs who and what connects rather than analysing traffic flows for anomalies. It is tempting because ISE provides network-wide endpoint visibility, but that visibility is identity and posture data, not NetFlow behavioural analytics.
- ✓
Cisco Secure Network Analytics (Stealthwatch)
Why this is correct
Cisco Secure Network Analytics, formerly Stealthwatch, consumes NetFlow and other flow telemetry to build network-wide visibility, then applies behavioural analytics and machine learning to flag anomalies such as unusual traffic patterns or potential exfiltration that signature-based tools would miss.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.