[May 07, 2024] Dumps Collection 200-201 Test Engine Dumps Training With 312 Questions [Q185-Q210]

Share

[May 07, 2024] Dumps Collection 200-201 Test Engine Dumps Training With 312 Questions

Cisco 200-201 Dumps - 100% Cover Real Exam Questions


Cisco 200-201 exam is a vendor-neutral certification that covers a broad range of cybersecurity topics. 200-201 exam is designed to help candidates gain a foundational understanding of cybersecurity operations and prepare them to take on entry-level cybersecurity roles. 200-201 exam is also an excellent starting point for individuals who wish to pursue more advanced certifications in cybersecurity.


Cisco 200-201 exam is an essential certification for cybersecurity professionals as it validates their skills and knowledge in the field. By obtaining this certification, individuals can demonstrate their expertise to potential employers and advance their careers in the cybersecurity industry. Overall, the Cisco 200-201 certification exam is an excellent opportunity for aspiring cybersecurity professionals to establish their credentials and gain recognition in the field.

 

NEW QUESTION # 185
Which system monitors local system operation and local network access for violations of a security policy?

  • A. systems-based sandboxing
  • B. host-based firewall
  • C. host-based intrusion detection
  • D. antivirus

Answer: C

Explanation:
Explanation
HIDS is capable of monitoring the internals of a computing system as well as the network packets on its network interfaces. Host-based firewall is a piece of software running on a single Host that can restrict incoming and outgoing Network activity for that host only.


NEW QUESTION # 186
Which two elements are assets in the role of attribution in an investigation? (Choose two.)

  • A. laptop
  • B. threat actor
  • C. firewall logs
  • D. context
  • E. session

Answer: B,D


NEW QUESTION # 187
What is the difference between statistical detection and rule-based detection models?

  • A. Rule-based detection involves the collection of data in relation to the behavior of legitimate users over a period of time
  • B. Statistical detection defines legitimate data of users over a period of time and rule-based detection defines it on an IF/THEN basis
  • C. Rule-based detection defines legitimate data of users over a period of time and statistical detection defines it on an IF/THEN basis
  • D. Statistical detection involves the evaluation of an object on its intended actions before it executes that behavior

Answer: B


NEW QUESTION # 188
What is an attack surface as compared to a vulnerability?

  • A. the sum of all paths for data into and out of the environment
  • B. an exploitable weakness in a system or its design
  • C. the individuals who perform an attack
  • D. any potential danger to an asset

Answer: B

Explanation:
An attack surface is the total sum of vulnerabilities that can be exploited to carry out a security attack. Attack surfaces can be physical or digital. The term attack surface is often confused with the term attack vector, but they are not the same thing. The surface is what is being attacked; the vector is the means by which an intruder gains access.


NEW QUESTION # 189
Which process is used when IPS events are removed to improve data integrity?

  • A. data protection
  • B. data signature
  • C. data availability
  • D. data normalization

Answer: D


NEW QUESTION # 190
Refer to the exhibit.

Which packet contains a file that is extractable within Wireshark?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: A


NEW QUESTION # 191
Drag and drop the uses on the left onto the type of security system on the right.

Answer:

Explanation:


NEW QUESTION # 192
Refer to the exhibit.

A company employee is connecting to mail google.com from an endpoint device. The website is loaded but with an error. What is occurring?

  • A. DNS hijacking attack
  • B. Endpoint local time is invalid.
  • C. Certificate is not in trusted roots.
  • D. man-m-the-middle attack

Answer: C


NEW QUESTION # 193
Refer to the exhibit.

In which Linux log file is this output found?

  • A. /var/log/authorization.log
  • B. /var/log/dmesg
  • C. var/log/var.log
  • D. /var/log/auth.log

Answer: D


NEW QUESTION # 194
Refer to the exhibit.

What is occurring in this network?

  • A. DNS cache poisoning
  • B. MAC flooding attack
  • C. ARP cache poisoning
  • D. MAC address table overflow

Answer: C


NEW QUESTION # 195
An organization has recently adjusted its security stance in response to online threats made by a known hacktivist group.
What is the initial event called in the NIST SP800-61?

  • A. trigger
  • B. instigator
  • C. precursor
  • D. online assault

Answer: C

Explanation:
Explanation
A precursor is a sign that a cyber-attack is about to occur on a system or network. An indicator is the actual alerts that are generated as an attack is happening. Therefore, as a security professional, it's important to know where you can find both precursor and indicator sources of information.
The following are common sources of precursor and indicator information:
* Security Information and Event Management (SIEM)
* Anti-virus and anti-spam software
* File integrity checking applications/software
* Logs from various sources (operating systems, devices, and applications)
* People who report a security incident
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf


NEW QUESTION # 196
One of the objectives of information security is to protect the CIA of information and systems.
What does CIA mean in this context?

  • A. confidentiality, identity, and authorization
  • B. confidentiality, integrity, and availability
  • C. confidentiality, integrity, and authorization
  • D. confidentiality, identity, and availability

Answer: B

Explanation:
Section: Security Concepts


NEW QUESTION # 197
Which process is used when IPS events are removed to improve data integrity?

  • A. data protection
  • B. data signature
  • C. data availability
  • D. data normalization

Answer: D

Explanation:
Section: Security Concepts


NEW QUESTION # 198
Which two elements are used for profiling a network? (Choose two.)

  • A. running processes
  • B. OS fingerprint
  • C. listening ports
  • D. session duration
  • E. total throughput

Answer: B,C


NEW QUESTION # 199
A user received a malicious attachment but did not run it. Which category classifies the intrusion?

  • A. installation
  • B. weaponization
  • C. reconnaissance
  • D. delivery

Answer: D


NEW QUESTION # 200
Which two pieces of information are collected from the IPv4 protocol header? (Choose two.)

  • A. UDP port to which the traffic is destined
  • B. source IP address of the packet
  • C. TCP port from which the traffic was sourced
  • D. UDP port from which the traffic is sourced
  • E. destination IP address of the packet

Answer: B,E

Explanation:
Section: Network Intrusion Analysis


NEW QUESTION # 201
Refer to the exhibit.

What is depicted in the exhibit?

  • A. UNIX-based syslog
  • B. Windows Event logs
  • C. Apache logs
  • D. IIS logs

Answer: C


NEW QUESTION # 202
What is the difference between mandatory access control (MAC) and discretionary access control (DAC)?

  • A. DAC is the strictest of all levels of control and MAC is object-based access
  • B. MAC is the strictest of all levels of control and DAC is object-based access
  • C. MAC is controlled by the discretion of the owner and DAC is controlled by an administrator
  • D. DAC is controlled by the operating system and MAC is controlled by an administrator

Answer: B


NEW QUESTION # 203
Refer to the exhibit.

What does the output indicate about the server with the IP address 172.18.104.139?

  • A. open ports of a web server
  • B. open port of an FTP server
  • C. running processes of the server
  • D. open ports of an email server

Answer: D


NEW QUESTION # 204
Refer to the exhibit.

Which packet contains a file that is extractable within Wireshark?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: A


NEW QUESTION # 205
What is a sandbox interprocess communication service?

  • A. A collection of interfaces that allow for coordination of activities among processes.
  • B. A collection of rules within the sandbox that prevent the communication between sandboxes.
  • C. A collection of network services that are activated on an interface, allowing for inter-port communication.
  • D. A collection of host services that allow for communication between sandboxes.

Answer: A

Explanation:
Inter-process communication (IPC) allows communication between different processes. A process is one or more threads running inside its own, isolated address space.https://docs.legato.io/16_10/basicIPC.html


NEW QUESTION # 206
Refer to the exhibit.

Which stakeholders must be involved when a company workstation is compromised?

  • A. Employee 2, Employee 3, Employee 4, Employee 5
  • B. Employee 4, Employee 6, Employee 7
  • C. Employee 1 Employee 2, Employee 3, Employee 4, Employee 5, Employee 7
  • D. Employee 1, Employee 2, Employee 4, Employee 5

Answer: A


NEW QUESTION # 207
An employee reports that someone has logged into their system and made unapproved changes, files are out of order, and several documents have been placed in the recycle bin. The security specialist reviewed the system logs, found nothing suspicious, and was not able to determine what occurred. The software is up to date; there are no alerts from antivirus and no failed login attempts. What is causing the lack of data visibility needed to detect the attack?

  • A. The threat actor used a dictionary-based password attack to obtain credentials.
  • B. The threat actor gained access to the system by known credentials.
  • C. The threat actor used the teardrop technique to confuse and crash login services.
  • D. The threat actor used an unknown vulnerability of the operating system that went undetected.

Answer: B


NEW QUESTION # 208
Refer to the exhibit.

Which two elements in the table are parts of the 5-tuple? (Choose two.)

  • A. Initiator User
  • B. First Packet
  • C. Initiator IP
  • D. Source Port
  • E. Ingress Security Zone

Answer: C,D


NEW QUESTION # 209
Refer to the exhibit.

Which two elements in the table are parts of the 5-tuple? (Choose two.)

  • A. Initiator User
  • B. First Packet
  • C. Initiator IP
  • D. Source Port
  • E. Ingress Security Zone

Answer: C,D


NEW QUESTION # 210
......

Realistic PracticeTorrent 200-201 Dumps PDF - 100% Passing Guarantee: https://actual4test.practicetorrent.com/200-201-practice-exam-torrent.html