200-201 PDF Exam Material 2021 Realistic 200-201 Dumps Questions [Q87-Q108]

Share

200-201 PDF Exam Material 2021 Realistic 200-201 Dumps Questions 

Updated Cisco 200-201 Dumps – PDF & Online Engine


Certification Path for Cisco Cybersecurity Operations Fundamentals v1.0 (200-201 CBROPS)

This exam is designed for individuals seeking a role as an associate-level cybersecurity analyst and IT professionals desiring knowledge in Cybersecurity operations or those in pursuit of the Cisco Certified CyberOps Associate certification including:

  • Students pursuing a technical degree
  • Current IT professionals
  • Recent college graduates with a technical degree

It has no pre-requisite.

 

NEW QUESTION 87
Refer to the exhibit.

What is shown in this PCAP file?

  • A. The HTTP GET is encoded.
  • B. The User-Agent is Mozilla/5.0.
  • C. Timestamps are indicated with error.
  • D. The protocol is TCP.

Answer: C

 

NEW QUESTION 88
An engineer needs to have visibility on TCP bandwidth usage, response time, and latency, combined with deep packet inspection to identify unknown software by its network traffic flow. Which two features of Cisco Application Visibility and Control should the engineer use to accomplish this goal? (Choose two.)

  • A. application recognition
  • B. adaptive AVC
  • C. metrics collection and exporting
  • D. traffic filtering
  • E. management and reporting

Answer: A,E

 

NEW QUESTION 89
Drag and drop the access control models from the left onto the correct descriptions on the right.

Answer:

Explanation:

 

NEW QUESTION 90
An analyst is investigating a host in the network that appears to be communicating to a command and control server on the Internet. After collecting this packet capture, the analyst cannot determine the technique and payload used for the communication.

Which obfuscation technique is the attacker using?

  • A. Base64 encoding
  • B. ROT13 encryption
  • C. SHA-256 hashing
  • D. transport layer security encryption

Answer: D

 

NEW QUESTION 91
Which type of evidence supports a theory or an assumption that results from initial evidence?

  • A. probabilistic
  • B. corroborative
  • C. best
  • D. indirect

Answer: B

 

NEW QUESTION 92
Refer to the exhibit.

In which Linux log file is this output found?

  • A. /var/log/authorization.log
  • B. var/log/var.log
  • C. /var/log/dmesg
  • D. /var/log/auth.log

Answer: D

 

NEW QUESTION 93
Which signature impacts network traffic by causing legitimate traffic to be blocked?

  • A. true positive
  • B. false positive
  • C. true negative
  • D. false negative

Answer: B

 

NEW QUESTION 94
Refer to the exhibit.

An analyst received this alert from the Cisco ASA device, and numerous activity logs were produced. How should this type of evidence be categorized?

  • A. circumstantial
  • B. corroborative
  • C. best
  • D. indirect

Answer: C

 

NEW QUESTION 95
An analyst is exploring the functionality of different operating systems.
What is a feature of Windows Management Instrumentation that must be considered when deciding on an operating system?

  • A. deploys Windows Operating Systems in an automated fashion
  • B. is an efficient tool for working with Active Directory
  • C. queries Linux devices that have Microsoft Services for Linux installed
  • D. has a Common Information Model, which describes installed hardware and software

Answer: D

 

NEW QUESTION 96
Refer to the exhibit.

What does the output indicate about the server with the IP address 172.18.104.139?

  • A. open port of an FTP server
  • B. running processes of the server
  • C. open ports of a web server
  • D. open ports of an email server

Answer: D

 

NEW QUESTION 97

Refer to the exhibit. What does the output indicate about the server with the IP address 172.18.104.139?

  • A. open port of an FTP server
  • B. running processes of the server
  • C. open ports of a web server
  • D. open ports of an email server

Answer: D

Explanation:
Section: Security Monitoring

 

NEW QUESTION 98
Which system monitors local system operation and local network access for violations of a security policy?

  • A. antivirus
  • B. host-based firewall
  • C. host-based intrusion detection
  • D. systems-based sandboxing

Answer: C

Explanation:
Explanation
HIDS is capable of monitoring the internals of a computing system as well as the network packets on its network interfaces. Host-based firewall is a piece of software running on a single Host that can restrict incoming and outgoing Network activity for that host only.

 

NEW QUESTION 99
An engineer receives a security alert that traffic with a known TOR exit node has occurred on the network.
What is the impact of this traffic?

  • A. ransomware communicating after infection
  • B. users downloading copyrighted content
  • C. user circumvention of the firewall
  • D. data exfiltration

Answer: C

 

NEW QUESTION 100

Refer to the exhibit. Which type of log is displayed?

  • A. IDS
  • B. proxy
  • C. sys
  • D. NetFlow

Answer: C

 

NEW QUESTION 101
An engineer received an alert affecting the degraded performance of a critical server. Analysis showed a heavy CPU and memory load. What is the next step the engineer should take to investigate this resource usage?

  • A. Run "ps -u" to find out who executed additional processes that caused a high load on a server.
  • B. Run "ps -d" to decrease the priority state of high load processes to avoid resource exhaustion.
  • C. Run "ps -ef" to understand which processes are taking a high amount of resources.
  • D. Run "ps -m" to capture the existing state of daemons and map required processes to find the gap.

Answer: D

 

NEW QUESTION 102
Refer to the exhibit.

Which event is occurring?

  • A. A URL is being evaluated to see if it has a malicious binary
  • B. A binary named "submit" is running on VM cuckoo1.
  • C. A binary on VM cuckoo1 is being submitted for evaluation
  • D. A binary is being submitted to run on VM cuckoo1

Answer: C

 

NEW QUESTION 103
An analyst is investigating a host in the network that appears to be communicating to a command and control server on the Internet. After collecting this packet capture the analyst cannot determine the technique and payload used for the communication.

Which obfuscation technique is the attacker using?

  • A. Base64 encoding
  • B. ROT13 encryption
  • C. SHA-256 hashing
  • D. transport layer security encryption

Answer: D

 

NEW QUESTION 104
An analyst received an alert on their desktop computer showing that an attack was successful on the host. After investigating, the analyst discovered that no mitigation action occurred during the attack. What is the reason for this discrepancy?

  • A. The computer has a NIDS installed on it.
  • B. The computer has a NIPS installed on it.
  • C. The computer has a HIPS installed on it.
  • D. The computer has a HIDS installed on it.

Answer: D

 

NEW QUESTION 105
Refer to the exhibit.

Which kind of attack method is depicted in this string?

  • A. SQL injection
  • B. denial of service
  • C. cross-site scripting
  • D. man-in-the-middle

Answer: C

 

NEW QUESTION 106
An analyst discovers that a legitimate security alert has been dismissed. Which signature caused this impact on network traffic?

  • A. true positive
  • B. true negative
  • C. false positive
  • D. false negative

Answer: D

 

NEW QUESTION 107
Which attack method intercepts traffic on a switched network?

  • A. denial of service
  • B. DHCP snooping
  • C. ARP cache poisoning
  • D. command and control

Answer: C

Explanation:
Explanation
An ARP-based MITM attack is achieved when an attacker poisons the ARP cache of two devices with the MAC address of the attacker's network interface card (NIC). Once the ARP caches have been successfully poisoned, each victim device sends all its packets to the attacker when communicating to the other device and puts the attacker in the middle of the communications path between the two victim devices. It allows an attacker to easily monitor all communication between victim devices. The intent is to intercept and view the information being passed between the two victim devices and potentially introduce sessions and traffic between the two victim devices

 

NEW QUESTION 108
......


The benefit in Obtaining the Cisco Cybersecurity Operations Fundamentals v1.0 (200-201 CBROPS)

This exam will help you:

  • Learn the fundamental skills, techniques, technologies, and the hands-on practice necessary to prevent and defend against cyberattacks as part of a SOC team
  • Earns you the Cisco Certified CyberOps Associate certification

 

Cisco 200-201 Dumps PDF Are going to be The Best Score: https://www.practicetorrent.com/200-201-practice-exam-torrent.html

200-201.pdf - Questions Answers PDF Sample Questions Reliable: https://drive.google.com/open?id=13bDzR-PZWfgekUOBxcvp2ffDMbtPmxCa