Latest 200-201 Exam Real Tests Free Updated Today [Q152-Q168]

Share

Latest 200-201 Exam Real Tests Free Updated Today

200-201 Real Exam Question Answers Updated [Feb 16, 2024]


Security Monitoring

The questions from this part cover 25% of the entire content and are dedicated to validating the following expertise:

  • Describing the utilization of metadata, full packet capture, as well as session, transaction, statistical, and alert data in security control;
  • Describing the network attacks, including denial of service, protocol-based, man-in-the-middle, and distributed denial of service;
  • Describing the obfuscation & evasion techniques, including proxies, encryption, and tunneling;
  • Describing the web app attacks, such as command injections, cross-site scripting, and SQL injection;
  • Comparing vulnerability and attack surface;
  • Describing the influence of certificates on security.
  • Describing the influence of access control program, tunneling & encryption, encapsulation & load balancing, as well as NAT/PAT, P2P, and TOR on information visibility;

Cisco 200-201 is a certification exam designed for professionals who are interested in gaining knowledge and skills in cybersecurity operations. 200-201 exam is designed to test the candidate's understanding of the fundamentals of cybersecurity operations, including security concepts, network security technologies, and security monitoring. 200-201 exam is also intended to verify the candidate's abilities to identify and respond to cybersecurity threats and attacks.


Cisco 200-201 exam is a valuable certification for individuals looking to start or advance their careers in cybersecurity operations. It is a recognized industry certification that demonstrates a candidate’s knowledge and skills in this field. By passing the exam, candidates can demonstrate to employers that they have the skills and knowledge necessary to identify and respond to security incidents in a network environment.

 

NEW QUESTION # 152
A SOC analyst is investigating an incident that involves a Linux system that is identifying specific sessions.
Which identifier tracks an active program?

  • A. active process identification number
  • B. application identification number
  • C. runtime identification number
  • D. process identification number

Answer: D

Explanation:
Section: Host-Based Analysis


NEW QUESTION # 153
An engineer is analyzing a recent breach where confidential documents were altered and stolen by the receptionist Further analysis shows that the threat actor connected an externa USB device to bypass security restrictions and steal data The engineer could not find an external USB device Which piece of information must an engineer use for attribution in an investigation?

  • A. list of security restrictions and privileges boundaries bypassed
  • B. receptionist and the actions performed
  • C. stolen data and its criticality assessment
  • D. external USB device

Answer: B


NEW QUESTION # 154
How does an attacker observe network traffic exchanged between two users?

  • A. command injection
  • B. port scanning
  • C. man-in-the-middle
  • D. denial of service

Answer: C


NEW QUESTION # 155

Refer to the exhibit. What should be interpreted from this packet capture?

  • A. IP address 192.168.122.100/50272/81.179.179.69/80/6 is sending a packet from port 50272 of IP address
    192.168.122.100 that is going to port 80 of IP address 81.179.179.69 using IP protocol 6.
  • B. IP address 179.179.69/50272/192.168.122.100/80/6 is sending a packet from port 80 of IP address
    192.168.122.100 that is going to port 50272 of IP address 81.179.179.69 using IP protocol 6.
  • C. IP address 179.179.69/50272/192.168.122.100/80/6 is sending a packet from port 50272 of IP address
    192.168.122.100 that is going to port 80 of IP address 81.179.179.69 using IP protocol 6.
  • D. IP address 192.168.122.100/50272/81.179.179.69/80/6 is sending a packet from port 80 of IP address
    192.168.122.100 that is going to port 50272 of IP address 81.179.179.69 using IP protocol 6.

Answer: A

Explanation:
Section: Security Monitoring


NEW QUESTION # 156
Which type of evidence supports a theory or an assumption that results from initial evidence?

  • A. best
  • B. indirect
  • C. probabilistic
  • D. corroborative

Answer: D

Explanation:
Section: Security Policies and Procedures


NEW QUESTION # 157
A security engineer deploys an enterprise-wide host/endpoint technology for all of the company's corporate PCs. Management requests the engineer to block a selected set of applications on all PCs.
Which technology should be used to accomplish this task?

  • A. antivirus/antispyware software
  • B. host-based IDS
  • C. network NGFW
  • D. application whitelisting/blacklisting

Answer: D

Explanation:
Section: Network Intrusion Analysis


NEW QUESTION # 158
An analyst is investigating an incident in a SOC environment. Which method is used to identify a session from a group of logs?

  • A. timestamps
  • B. sequence numbers
  • C. 5-tuple
  • D. IP identifier

Answer: C


NEW QUESTION # 159
What describes the concept of data consistently and readily being accessible for legitimate users?

  • A. availability
  • B. confidentiality
  • C. accessibility
  • D. integrity

Answer: A


NEW QUESTION # 160
What are two differences in how tampered and untampered disk images affect a security incident? (Choose two.)

  • A. Tampered images are used in the security investigation process
  • B. The image is tampered if the stored hash and the computed hash match
  • C. Tampered images are used in the incident recovery process
  • D. Untampered images are used in the security investigation process
  • E. The image is untampered if the stored hash and the computed hash match

Answer: D,E

Explanation:
Explanation
Cert Guide by Omar Santos, Chapter 9 - Introduction to digital Forensics. "When you collect evidence, you must protect its integrity. This involves making sure that nothing is added to the evidence and that nothing is deleted or destroyed (this is known as evidence preservation)."


NEW QUESTION # 161
An analyst is using the SIEM platform and must extract a custom property from a Cisco device and capture the phrase, "File: Clean." Which regex must the analyst import?

  • A. File: Clean (.*)
  • B. File: Clean
  • C. ^File: Clean$
  • D. ^Parent File Clean$

Answer: B


NEW QUESTION # 162
Refer to the exhibit.

What does the output indicate about the server with the IP address 172.18.104.139?

  • A. open port of an FTP server
  • B. running processes of the server
  • C. open ports of an email server
  • D. open ports of a web server

Answer: C


NEW QUESTION # 163
Refer to the exhibit.

Drag and drop the element name from the left onto the correct piece of the PCAP file on the right.

Answer:

Explanation:


NEW QUESTION # 164
How does statistical detection differ from rule-based detection?

  • A. Statistical detection defines legitimate data over time, and rule-based detection works on a predefined set of rules
  • B. Rule-based detection involves the evaluation of events, and statistical detection requires an evaluated set of events to function Rule-based detection defines
  • C. legitimate data over a period of time, and statistical detection works on a predefined set of rules
  • D. Statistical detection involves the evaluation of events, and rule-based detection requires an evaluated set of events to function.

Answer: A


NEW QUESTION # 165
An organization's security team has detected network spikes coming from the internal network. An investigation has concluded that the spike in traffic was from intensive network scanning How should the analyst collect the traffic to isolate the suspicious host?

  • A. by most used ports
  • B. by most active source IP
  • C. based on the protocols used
  • D. based on the most used applications

Answer: B


NEW QUESTION # 166
What is the practice of giving employees only those permissions necessary to perform their specific role within an organization?

  • A. need to know
  • B. due diligence
  • C. integrity validation
  • D. least privilege

Answer: D

Explanation:
Section: Security Concepts


NEW QUESTION # 167
What is the difference between mandatory access control (MAC) and discretionary access control (DAC)?

  • A. MAC is controlled by the discretion of the owner and DAC is controlled by an administrator
  • B. MAC is the strictest of all levels of control and DAC is object-based access
  • C. DAC is the strictest of all levels of control and MAC is object-based access
  • D. DAC is controlled by the operating system and MAC is controlled by an administrator

Answer: B

Explanation:
Section: Security Concepts


NEW QUESTION # 168
......

Latest 200-201 Study Guides 2024 - With Test Engine PDF: https://www.passleadervce.com/CyberOps-Associate/reliable-200-201-exam-learning-guide.html

Easily To Pass New Cisco 200-201 Dumps with 260 Questions: https://drive.google.com/open?id=14o1HgVolT2MEap9AqmweYaAaLilW8iGV