Best Quality Cisco 200-201 Exam Questions BraindumpsPrep Realistic Practice Exams [2021]
Critical Information To Understanding Cisco Cybersecurity Operations Fundamentals Pass the First Time
NEW QUESTION 108
Which attack is the network vulnerable to when a stream cipher like RC4 is used twice with the same key?
- A. plaintext-only attack
- B. ciphertext-only attack
- C. meet-in-the-middle attack
- D. forgery attack
Answer: B
Explanation:
Explanation/Reference:
NEW QUESTION 109
A SOC analyst is investigating an incident that involves a Linux system that is identifying specific sessions.
Which identifier tracks an active program?
- A. runtime identification number
- B. application identification number
- C. active process identification number
- D. process identification number
Answer: D
Explanation:
Section: Host-Based Analysis
NEW QUESTION 110
While viewing packet capture data, an analyst sees that one IP is sending and receiving traffic for multiple devices by modifying the IP header.
Which technology makes this behavior possible?
- A. encapsulation
- B. NAT
- C. TOR
- D. tunneling
Answer: B
Explanation:
Section: Network Intrusion Analysis
NEW QUESTION 111
An organization's security team has detected network spikes coming from the internal network. An investigation has concluded that the spike in traffic was from intensive network scanning How should the analyst collect the traffic to isolate the suspicious host?
- A. based on the most used applications
- B. based on the protocols used
- C. by most active source IP
- D. by most used ports
Answer: B
NEW QUESTION 112
Refer to the exhibit.
What information is depicted?
- A. IIS data
- B. IPS event data
- C. NetFlow data
- D. network discovery event
Answer: C
NEW QUESTION 113
A security engineer deploys an enterprise-wide host/endpoint technology for all of the company's corporate PCs. Management requests the engineer to block a selected set of applications on all PCs.
Which technology should be used to accomplish this task?
- A. host-based IDS
- B. application whitelisting/blacklisting
- C. antivirus/antispyware software
- D. network NGFW
Answer: B
NEW QUESTION 114
Refer to the exhibit.
What is occurring in this network?
- A. ARP cache poisoning
- B. MAC address table overflow
- C. MAC flooding attack
- D. DNS cache poisoning
Answer: A
NEW QUESTION 115
Which filter allows an engineer to filter traffic in Wireshark to further analyze the PCAP file by only showing the traffic for LAN 10.11.x.x, between workstations and servers without the Internet?
- A. src==10.11.0.0/16 and dst==10.11.0.0/16
- B. ip.src==10.11.0.0/16 and ip.dst==10.11.0.0/16
- C. src=10.11.0.0/16 and dst=10.11.0.0/16
- D. ip.src=10.11.0.0/16 and ip.dst=10.11.0.0/16
Answer: B
NEW QUESTION 116
Refer to the exhibit.
What information is depicted?
- A. IIS data
- B. IPS event data
- C. NetFlow data
- D. network discovery event
Answer: C
NEW QUESTION 117
How is attacking a vulnerability categorized?
- A. delivery
- B. action on objectives
- C. installation
- D. exploitation
Answer: D
NEW QUESTION 118
Drag and drop the access control models from the left onto the correct descriptions on the right.
Answer:
Explanation:
NEW QUESTION 119
An engineer discovered a breach, identified the threat's entry point, and removed access. The engineer was able to identify the host, the IP address of the threat actor, and the application the threat actor targeted. What is the next step the engineer should take according to the NIST SP 800-61 Incident handling guide?
- A. Reduce the probability of similar threats.
- B. Recover from the threat.
- C. Identify lessons learned from the threat.
- D. Analyze the threat.
Answer: A
NEW QUESTION 120
Refer to the exhibit.
Which event is occurring?
- A. A URL is being evaluated to see if it has a malicious binary
- B. A binary on VM cuckoo1 is being submitted for evaluation
- C. A binary is being submitted to run on VM cuckoo1
- D. A binary named "submit" is running on VM cuckoo1.
Answer: B
NEW QUESTION 121 
Refer to the exhibit. Which two elements in the table are parts of the 5-tuple? (Choose two.)
- A. First Packet
- B. Ingress Security Zone
- C. Initiator User
- D. Initiator IP
- E. Source Port
Answer: D,E
NEW QUESTION 122
Refer to the exhibit.
Which two elements in the table are parts of the 5-tuple? (Choose two.)
- A. First Packet
- B. Ingress Security Zone
- C. Initiator User
- D. Initiator IP
- E. Source Port
Answer: D,E
NEW QUESTION 123
......
200-201 EXAM DUMPS WITH GUARANTEED SUCCESS: https://www.briandumpsprep.com/200-201-prep-exam-braindumps.html
Best Quality Cisco 200-201 Exam Questions: https://drive.google.com/open?id=1yVEzD2_eWGI1WIdRQuSK6lYYaQlUhbqW
