Verified 200-201 Q&As - Pass Guarantee 200-201 Exam Dumps [Q69-Q93]

Share

Verified 200-201 Q&As - Pass Guarantee 200-201 Exam Dumps

Check the Free demo of our 200-201 Exam Dumps with 260 Questions

NEW QUESTION # 69
Which NIST IR category stakeholder is responsible for coordinating incident response among various business units, minimizing damage, and reporting to regulatory agencies?

  • A. public affairs
  • B. CSIRT
  • C. management
  • D. PSIRT

Answer: C


NEW QUESTION # 70
Which category relates to improper use or disclosure of PII data?

  • A. legal
  • B. compliance
  • C. contractual
  • D. regulated

Answer: D

Explanation:
Section: Security Policies and Procedures


NEW QUESTION # 71
What does cyber attribution identity in an investigation?

  • A. cause of an attack
  • B. vulnerabilities exploited
  • C. threat actors of an attack
  • D. exploit of an attack

Answer: C


NEW QUESTION # 72
What is a difference between SIEM and SOAR?

  • A. SlEM's primary function is to collect and detect anomalies, while SOAR is more focused on security operations automation and response.
  • B. SIEM predicts and prevents security alerts, while SOAR checks attack patterns and applies the mitigation.
  • C. SOAR predicts and prevents security alerts, while SIEM checks attack patterns and applies the mitigation.
  • D. SOAR's primary function is to collect and detect anomalies, while SIEM is more focused on security operations automation and response.

Answer: D


NEW QUESTION # 73
A SOC analyst is investigating an incident that involves a Linux system that is identifying specific sessions.
Which identifier tracks an active program?

  • A. runtime identification number
  • B. active process identification number
  • C. application identification number
  • D. process identification number

Answer: D

Explanation:
Section: Host-Based Analysis


NEW QUESTION # 74
What is an example of social engineering attacks?

  • A. receiving an invitation to the department's weekly WebEx meeting
  • B. receiving an unexpected email from an unknown person with an uncharacteristic attachment from someone in the same company
  • C. sending a verbal request to an administrator who knows how to change an account password
  • D. receiving an email from human resources requesting a visit to their secure website to update contact information

Answer: D


NEW QUESTION # 75
An analyst discovers that a legitimate security alert has been dismissed. Which signature caused this impact on network traffic?

  • A. false negative
  • B. false positive
  • C. true positive
  • D. true negative

Answer: A


NEW QUESTION # 76
During which phase of the forensic process are tools and techniques used to extract information from the collected data?

  • A. examination
  • B. reporting
  • C. collection
  • D. investigation

Answer: C


NEW QUESTION # 77
Drag and drop the technology on the left onto the data type the technology provides on the right.

Answer:

Explanation:


NEW QUESTION # 78
What makes HTTPS traffic difficult to monitor?

  • A. packet header size
  • B. encryption
  • C. SSL interception
  • D. signature detection time

Answer: B


NEW QUESTION # 79
Refer to the exhibit.

A network administrator is investigating suspicious network activity by analyzing captured traffic. An engineer notices abnormal behavior and discovers that the default user agent is present in the headers of requests and data being transmitted What is occurring?

  • A. cache bypassing attack: attacker is sending requests for noncacheable content
  • B. indicators of denial-of-service attack due to the frequency of requests
  • C. indicators of data exfiltration HTTP requests must be plain text
  • D. garbage flood attack attacker is sending garbage binary data to open ports

Answer: C


NEW QUESTION # 80
A security engineer has a video of a suspect entering a data center that was captured on the same day that files in the same data center were transferred to a competitor.
Which type of evidence is this?

  • A. indirect evidence
  • B. best evidence
  • C. physical evidence
  • D. prima facie evidence

Answer: A

Explanation:
Explanation
There are three general types of evidence:
--> Best evidence: can be presented in court in the original form (for example, an exact copy of a hard disk drive).
--> Corroborating evidence: tends to support a theory or an assumption deduced by some initial evidence. This corroborating evidence confirms the proposition.
--> Indirect or circumstantial evidence: extrapolation to a conclusion of fact (such as fingerprints, DNA evidence, and so on).


NEW QUESTION # 81
An employee reports that someone has logged into their system and made unapproved changes, files are out of order, and several documents have been placed in the recycle bin. The security specialist reviewed the system logs, found nothing suspicious, and was not able to determine what occurred. The software is up to date; there are no alerts from antivirus and no failed login attempts. What is causing the lack of data visibility needed to detect the attack?

  • A. The threat actor gained access to the system by known credentials.
  • B. The threat actor used an unknown vulnerability of the operating system that went undetected.
  • C. The threat actor used the teardrop technique to confuse and crash login services.
  • D. The threat actor used a dictionary-based password attack to obtain credentials.

Answer: A


NEW QUESTION # 82
A user received a malicious attachment but did not run it.
Which category classifies the intrusion?

  • A. weaponization
  • B. installation
  • C. delivery
  • D. reconnaissance

Answer: C


NEW QUESTION # 83
According to the NIST SP 800-86. which two types of data are considered volatile? (Choose two.)

  • A. temporary files
  • B. swap files
  • C. login sessions
  • D. dump files
  • E. free space

Answer: C,E


NEW QUESTION # 84
Refer to the exhibit.

Which application protocol is in this PCAP file?

  • A. SSH
  • B. TCP
  • C. TLS
  • D. HTTP

Answer: B


NEW QUESTION # 85
DRAG DROP
Drag and drop the security concept on the left onto the example of that concept on the right.
Select and Place:

Answer:

Explanation:


NEW QUESTION # 86

Refer to the exhibit. Which event is occurring?

  • A. A URL is being evaluated to see if it has a malicious binary
  • B. A binary is being submitted to run on VM cuckoo1
  • C. A binary on VM cuckoo1 is being submitted for evaluation
  • D. A binary named "submit" is running on VM cuckoo1.

Answer: C


NEW QUESTION # 87
A user received a malicious attachment but did not run it. Which category classifies the intrusion?

  • A. weaponization
  • B. installation
  • C. delivery
  • D. reconnaissance

Answer: C


NEW QUESTION # 88
Which two pieces of information are collected from the IPv4 protocol header? (Choose two.)

  • A. UDP port from which the traffic is sourced
  • B. destination IP address of the packet
  • C. UDP port to which the traffic is destined
  • D. source IP address of the packet
  • E. TCP port from which the traffic was sourced

Answer: B,D


NEW QUESTION # 89
Which attack method intercepts traffic on a switched network?

  • A. command and control
  • B. ARP cache poisoning
  • C. denial of service
  • D. DHCP snooping

Answer: D

Explanation:
Section: Security Concepts


NEW QUESTION # 90
Which process is used when IPS events are removed to improve data integrity?

  • A. data signature
  • B. data availability
  • C. data normalization
  • D. data protection

Answer: C

Explanation:
Section: Security Concepts


NEW QUESTION # 91
How does an SSL certificate impact security between the client and the server?

  • A. by creating an integrated channel between the client and the server
  • B. by enabling an authenticated channel between the client and the server
  • C. by enabling an authorized channel between the client and the server
  • D. by creating an encrypted channel between the client and the server
    Section: (none)
    Explanation

Answer: D


NEW QUESTION # 92
Syslog collecting software is installed on the server For the log containment, a disk with FAT type partition is used An engineer determined that log files are being corrupted when the 4 GB tile size is exceeded. Which action resolves the issue?

  • A. Add space to the existing partition and lower the retention penod.
  • B. Use the Ext4 partition because it can hold files up to 16 TB.
  • C. Use FAT32 to exceed the limit of 4 GB.
  • D. Use NTFS partition for log file containment

Answer: D


NEW QUESTION # 93
......

Get professional help from our 200-201 Dumps PDF: https://www.examprepaway.com/Cisco/braindumps.200-201.ete.file.html

Clear your concepts with 200-201 Questions Before Attempting Real exam: https://drive.google.com/open?id=1F5WXbu9FvyBjSX7j08M_R76xmPYWY1iA