[Mar 07, 2023] Updates Up to 365 days On Valid 200-201 Braindumps [Q124-Q139]

Share

[Mar 07, 2023] Updates Up to 365 days On Valid 200-201 Braindumps

Best Quality200-201 Exam Questions Cisco Test To Gain Brilliante Result

NEW QUESTION 124
Drag and drop the technology on the left onto the data type the technology provides on the right.

Answer:

Explanation:

 

NEW QUESTION 125
Which data format is the most efficient to build a baseline of traffic seen over an extended period of time?

  • A. firewall event logs
  • B. NetFlow
  • C. full packet capture
  • D. syslog messages

Answer: B

Explanation:
Section: Security Monitoring

 

NEW QUESTION 126
Which action should be taken if the system is overwhelmed with alerts when false positives and false negatives are compared?

  • A. Design criteria for reviewing alerts.
  • B. Adjust the alerts schedule.
  • C. Redefine signature rules.
  • D. Modify the settings of the intrusion detection system.

Answer: D

 

NEW QUESTION 127
Refer to the exhibit.

An engineer is reviewing a Cuckoo report of a file. What must the engineer interpret from the report?

  • A. The file will appear legitimate by evading signature-based detection.
  • B. The file will not execute its behavior in a sandbox environment to avoid detection.
  • C. The file will insert itself into an application and execute when the application is run.
  • D. The file will monitor user activity and send the information to an outside source.

Answer: B

 

NEW QUESTION 128
Refer to the exhibit.

What is depicted in the exhibit?

  • A. UNIX-based syslog
  • B. Apache logs
  • C. Windows Event logs
  • D. IIS logs

Answer: A

 

NEW QUESTION 129
Refer to the exhibit.

Which application protocol is in this PCAP file?

  • A. TCP
  • B. HTTP
  • C. TLS
  • D. SSH

Answer: A

 

NEW QUESTION 130
Refer to the exhibit.

Which technology generates this log?

  • A. IDS
  • B. NetFlow
  • C. firewall
  • D. web proxy

Answer: C

 

NEW QUESTION 131
Refer to the exhibit.

Which field contains DNS header information if the payload is a query or a response?

  • A. QR
  • B. TC
  • C. ID
  • D. Z

Answer: C

 

NEW QUESTION 132
Refer to the exhibit.

An engineer is analyzing a PCAP file after a recent breach An engineer identified that the attacker used an aggressive ARP scan to scan the hosts and found web and SSH servers. Further analysis showed several SSH Server Banner and Key Exchange Initiations. The engineer cannot see the exact data being transmitted over an encrypted channel and cannot identify how the attacker gained access How did the attacker gain access?

  • A. by using an SSH Tectia Server vulnerability to enable host-based authentication
  • B. by using the buffer overflow in the URL catcher feature for SSH
  • C. by using an SSH vulnerability to silently redirect connections to the local host
  • D. by using brute force on the SSH service to gain access

Answer: C

 

NEW QUESTION 133
How does an attack surface differ from an attack vector?

  • A. An attack vector recognizes the potential outcomes of an attack, and the attack surface is choosing a method of an attack.
  • B. An attack surface mitigates external vulnerabilities, and an attack vector identifies mitigation techniques and possible workarounds.
  • C. An attack surface identifies vulnerable parts for an attack, and an attack vector specifies which attacks are feasible to those parts.
  • D. An attack vector matches components that can be exploited, and an attack surface classifies the potential path for exploitation

Answer: B

 

NEW QUESTION 134
Which attack is the network vulnerable to when a stream cipher like RC4 is used twice with the same key?

  • A. plaintext-only attack
  • B. meet-in-the-middle attack
  • C. ciphertext-only attack
  • D. forgery attack

Answer: C

 

NEW QUESTION 135
Which type of data collection requires the largest amount of storage space?

  • A. alert data
  • B. full packet capture
  • C. session data
  • D. transaction data

Answer: B

Explanation:
Section: Network Intrusion Analysis

 

NEW QUESTION 136
Refer to the exhibit.

What is the potential threat identified in this Stealthwatch dashboard?

  • A. A policy violation is active for host 10.201.3.149.
  • B. A policy violation is active for host 10.10.101.24.
  • C. A host on the network is sending a DDoS attack to another inside host.
  • D. There are two active data exfiltration alerts.

Answer: D

 

NEW QUESTION 137
What is a difference between signature-based and behavior-based detection?

  • A. Signature-based uses a known vulnerability database, while behavior-based intelligently summarizes existing data.
  • B. Behavior-based uses a known vulnerability database, while signature-based intelligently summarizes existing data.
  • C. Behavior-based identifies behaviors that may be linked to attacks, while signature-based has a predefined set of rules to match before an alert.
  • D. Signature-based identifies behaviors that may be linked to attacks, while behavior-based has a predefined set of rules to match before an alert.

Answer: A

 

NEW QUESTION 138
Drag and drop the security concept on the left onto the example of that concept on the right.

Answer:

Explanation:

 

NEW QUESTION 139
......

Focus on 200-201 All-in-One Exam Guide For Quick Preparation: https://www.testkingpdf.com/200-201-testking-pdf-torrent.html

Tested Material Used To 200-201: https://drive.google.com/open?id=1DYslg1YtrLzmx4mfwC-v88N64VW8WU0k