[UPDATED 2024] Cisco 200-201 Questions Prepare with Free Demo of PDF
NEW 2024 Certification Sample Questions 200-201 Dumps & Practice Exam
Cisco 200-201 certification exam is designed for individuals who are interested in pursuing a career in cybersecurity. 200-201 exam focuses on understanding the fundamentals of cybersecurity operations and is an entry-level certification exam. It is ideal for individuals who are new to the field of cybersecurity or have limited experience in this area.
Preparing for the Cisco 200-201 certification exam involves studying and practicing the concepts covered in the exam. Cisco offers a range of resources to help individuals prepare for the exam, including study guides, online courses, and practice exams. With the right preparation, individuals can feel confident in their ability to pass the Cisco 200-201 certification exam and kickstart their career in cybersecurity.
NEW QUESTION # 108
A company is using several network applications that require high availability and responsiveness, such that milliseconds of latency on network traffic is not acceptable. An engineer needs to analyze the network and identify ways to improve traffic movement to minimize delays. Which information must the engineer obtain for this analysis?
- A. output of routing protocol authentication failures and ports used
- B. running processes on the applications and their total network usage
- C. deep packet captures of each application flow and duration
- D. total throughput on the interface of the router and NetFlow records
Answer: B
NEW QUESTION # 109
An organization has recently adjusted its security stance in response to online threats made by a known hacktivist group.
What is the initial event called in the NIST SP800-61?
- A. precursor
- B. online assault
- C. instigator
- D. trigger
Answer: A
Explanation:
A precursor is a sign that a cyber-attack is about to occur on a system or network. An indicator is the actual alerts that are generated as an attack is happening. Therefore, as a security professional, it's important to know where you can find both precursor and indicator sources of information.
The following are common sources of precursor and indicator information:
* Security Information and Event Management (SIEM)
* Anti-virus and anti-spam software
* File integrity checking applications/software
* Logs from various sources (operating systems, devices, and applications)
* People who report a security incident
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
NEW QUESTION # 110
Which two components reduce the attack surface on an endpoint? (Choose two.)
- A. full packet captures at the endpoint
- B. increased audit log levels
- C. load balancing
- D. secure boot
- E. restricting USB ports
Answer: D,E
NEW QUESTION # 111
Which evasion technique is a function of ransomware?
- A. encryption
- B. resource exhaustion
- C. extended sleep calls
- D. encoding
Answer: A
NEW QUESTION # 112
Refer to the exhibit.
What is the potential threat identified in this Stealthwatch dashboard?
- A. Host 10.201.3.149 is receiving almost 19 times more data than is being sent to host 152.46.6.91.
- B. Traffic to 152.46.6.149 is being denied by an Advanced Network Control policy.
- C. Host 152.46.6.91 is being identified as a watchlist country for data transfer.
- D. Host 10.201.3.149 is sending data to 152.46.6.91 using TCP/443.
Answer: A
NEW QUESTION # 113
What is the practice of giving employees only those permissions necessary to perform their specific role within an organization?
- A. integrity validation
- B. due diligence
- C. least privilege
- D. need to know
Answer: C
NEW QUESTION # 114
An engineer received an alert affecting the degraded performance of a critical server. Analysis showed a heavy CPU and memory load. What is the next step the engineer should take to investigate this resource usage?
- A. Run "ps -u" to find out who executed additional processes that caused a high load on a server.
- B. Run "ps -d" to decrease the priority state of high load processes to avoid resource exhaustion.
- C. Run "ps -m" to capture the existing state of daemons and map required processes to find the gap.
- D. Run "ps -ef" to understand which processes are taking a high amount of resources.
Answer: D
NEW QUESTION # 115
Refer to the exhibit.
Which kind of attack method is depicted in this string?
- A. cross-site scripting
- B. SQL injection
- C. man-in-the-middle
- D. denial of service
Answer: A
NEW QUESTION # 116
Refer to the exhibit.
Which component is identifiable in this exhibit?
- A. Windows Registry hive
- B. local service in the Windows Services Manager
- C. Windows PowerShell verb
- D. Trusted Root Certificate store on the local machine
Answer: A
Explanation:
https://docs.microsoft.com/en-us/windows/win32/sysinfo/registry-hives
https://ldapwiki.com/wiki/HKEY_LOCAL_MACHINE#:~:text=HKEY_LOCAL_MACHINE%20Windows%20
NEW QUESTION # 117
An engineer is analyzing a recent breach where confidential documents were altered and stolen by the receptionist Further analysis shows that the threat actor connected an externa USB device to bypass security restrictions and steal data The engineer could not find an external USB device Which piece of information must an engineer use for attribution in an investigation?
- A. external USB device
- B. receptionist and the actions performed
- C. stolen data and its criticality assessment
- D. list of security restrictions and privileges boundaries bypassed
Answer: B
NEW QUESTION # 118
A security engineer notices confidential data being exfiltrated to a domain "Ranso4134-mware31-895" address that is attributed to a known advanced persistent threat group The engineer discovers that the activity is part of a real attack and not a network misconfiguration. Which category does this event fall under as defined in the Cyber Kill Chain?
- A. weaponization
- B. delivery
- C. reconnaissance
- D. action on objectives
Answer: A
NEW QUESTION # 119
Which type of evidence supports a theory or an assumption that results from initial evidence?
- A. indirect
- B. corroborative
- C. probabilistic
- D. best
Answer: B
Explanation:
Section: Security Policies and Procedures
NEW QUESTION # 120
A user received a malicious attachment but did not run it.
Which category classifies the intrusion?
- A. delivery
- B. reconnaissance
- C. installation
- D. weaponization
Answer: A
NEW QUESTION # 121
Refer to the exhibit.
Which two elements in the table are parts of the 5-tuple? (Choose two.)
- A. Initiator User
- B. First Packet
- C. Initiator IP
- D. Source Port
- E. Ingress Security Zone
Answer: C,D
NEW QUESTION # 122
At which layer is deep packet inspection investigated on a firewall?
- A. application
- B. data link
- C. transport
- D. internet
Answer: A
Explanation:
Explanation
Deep packet inspection is a form of packet filtering usually carried out as a function of your firewall. It is applied at the Open Systems Interconnection's application layer. Deep packet inspection evaluates the contents of a packet that is going through a checkpoint.
NEW QUESTION # 123
......
In order to prepare for the exam, candidates can take advantage of various resources such as study guides, practice exams, and training courses. It is important for candidates to thoroughly prepare for the exam and gain a strong understanding of the exam objectives in order to pass with flying colors.
200-201 Deluxe Study Guide with Online Test Engine: https://torrentvce.certkingdompdf.com/200-201-latest-certkingdom-dumps.html