[2022] Pass Cisco 200-201 Test Practice Test Questions Exam Dumps
Verified 200-201 dumps Q&As - 200-201 dumps with Correct Answers
Career Path with Cisco 200-201 Exam
When you complete the Cisco 200-201 exam with flying colors, you will be awarded the Cisco Certified CyberOps Associate certification. This certificate can be very beneficial to you in many ways, including making you more employable. With this certification, you can apply for the following job roles:
- Data Analyst;
- IT Technician.
- Lead Security Technician;
- Cyber Security Engineer;
- Security Operations Manager;
You can also be able to negotiate for a good salary after getting certified. Currently, the professionals with this associate-level certification can earn an average annual salary of $100,000.
NEW QUESTION 128 
Refer to the exhibit. What is occurring in this network traffic?
- A. high rate of SYN packets being sent from a multiple source towards a single destination IP
- B. high rate of SYN packets being sent from a single source IP towards multiple destination IPs
- C. flood of SYN packets coming from a single source IP to a single destination IP
- D. flood of ACK packets coming from a single source IP to multiple destination IPs
Answer: C
Explanation:
Section: Security Monitoring
NEW QUESTION 129
A security engineer deploys an enterprise-wide host/endpoint technology for all of the company's corporate PCs. Management requests the engineer to block a selected set of applications on all PCs.
Which technology should be used to accomplish this task?
- A. host-based IDS
- B. antivirus/antispyware software
- C. network NGFW
- D. application whitelisting/blacklisting
Answer: D
Explanation:
Section: Network Intrusion Analysis
NEW QUESTION 130
What is the difference between inline traffic interrogation (TAPS) and traffic mirroring (SPAN)?
- A. TAPS interrogation is more complex because traffic mirroring applies additional tags to data and SPAN does not alter integrity and provides full duplex network.
- B. TAPS replicates the traffic to preserve integrity, and SPAN modifies packets before sending them to other analysis tools
- C. SPAN ports filter out physical layer errors, making some types of analyses more difficult, and TAPS receives all packets, including physical errors.
- D. SPAN results in more efficient traffic analysis, and TAPS is considerably slower due to latency caused by mirroring.
Answer: C
NEW QUESTION 131
A system administrator is ensuring that specific registry information is accurate.
Which type of configuration information does the HKEY_LOCAL_MACHINE hive contain?
- A. all users on the system, including visual settings
- B. currently logged in users, including folders and control panel settings
- C. file extension associations
- D. hardware, software, and security settings for the system
Answer: D
Explanation:
Explanation
https://docs.microsoft.com/en-us/troubleshoot/windows-server/performance/windows-registry-advanced-users
NEW QUESTION 132
Which security technology allows only a set of pre-approved applications to run on a system?
- A. application-level blacklisting
- B. antivirus
- C. application-level whitelisting
- D. host-based IPS
Answer: C
Explanation:
Section: Host-Based Analysis
NEW QUESTION 133
A security analyst notices a sudden surge of incoming traffic and detects unknown packets from unknown senders After further investigation, the analyst learns that customers claim that they cannot access company servers According to NIST SP800-61, in which phase of the incident response process is the analyst?
- A. post-incident activity
- B. preparation
- C. detection and analysis
- D. containment, eradication, and recovery
Answer: C
NEW QUESTION 134
What is a sandbox interprocess communication service?
- A. A collection of interfaces that allow for coordination of activities among processes.
- B. A collection of network services that are activated on an interface, allowing for inter-port communication.
- C. A collection of host services that allow for communication between sandboxes.
- D. A collection of rules within the sandbox that prevent the communication between sandboxes.
Answer: D
NEW QUESTION 135
Drag and drop the access control models from the left onto the correct descriptions on the right.
Answer:
Explanation:
NEW QUESTION 136
An investigator is examining a copy of an ISO file that is stored in CDFS format. What type of evidence is this file?
- A. data from a DVD copied using Windows system
- B. data from a CD copied using Windows
- C. data from a CD copied using Linux system
- D. data from a CD copied using Mac-based system
Answer: C
Explanation:
Explanation
CDfs is a virtual file system for Unix-like operating systems; it provides access to data and audio tracks on Compact Discs. When the CDfs driver mounts a Compact Disc, it represents each track as a file. This is consistent with the Unix convention "everything is a file". Source: https://en.wikipedia.org/wiki/CDfs
NEW QUESTION 137
Drag and drop the type of evidence from the left onto the description of that evidence on the right.
Answer:
Explanation:
Explanation
Graphical user interface, application Description automatically generated
NEW QUESTION 138
Which regular expression is needed to capture the IP address 192.168.20.232?
- A. ^ (?:[0-9]f1,3}\.){1,4}
- B. ^ (?:[0-9]{1,3}\.)'
- C. ^ ([0-9]-{3})
- D. ^ (?:[0-9]{1,3}\.){3}[0-9]{1,3}
Answer: D
NEW QUESTION 139
Refer to the exhibit.
What information is depicted?
- A. IIS data
- B. network discovery event
- C. IPS event data
- D. NetFlow data
Answer: D
NEW QUESTION 140
Refer to the exhibit.
In which Linux log file is this output found?
- A. var/log/var.log
- B. /var/log/auth.log
- C. /var/log/dmesg
- D. /var/log/authorization.log
Answer: B
NEW QUESTION 141
Refer to the exhibit.
An analyst received this alert from the Cisco ASA device, and numerous activity logs were produced. How should this type of evidence be categorized?
- A. circumstantial
- B. indirect
- C. corroborative
- D. best
Answer: D
NEW QUESTION 142
Which system monitors local system operation and local network access for violations of a security policy?
- A. systems-based sandboxing
- B. antivirus
- C. host-based firewall
- D. host-based intrusion detection
Answer: C
NEW QUESTION 143
Drag and drop the security concept from the left onto the example of that concept on the right.
Answer:
Explanation:
Explanation
Table Description automatically generated
NEW QUESTION 144
What is the difference between an attack vector and attack surface?
- A. An attack vector identifies the potential outcomes of an attack; and an attack surface launches an attack using several methods against the identified vulnerabilities.
- B. An attack surface recognizes which network parts are vulnerable to an attack; and an attack vector identifies which attacks are possible with these vulnerabilities.
- C. An attack vector identifies components that can be exploited; and an attack surface identifies the potential path an attack can take to penetrate the network.
- D. An attack surface identifies vulnerabilities that require user input or validation; and an attack vector identifies vulnerabilities that are independent of user actions.
Answer: B
NEW QUESTION 145
Refer to the exhibit.
Which frame numbers contain a file that is extractable via TCP stream within Wireshark?
- A. 7,14, and 21
- B. 7 to 21
- C. 14,16,18, and 19
- D. 7 and 21
Answer: D
NEW QUESTION 146
A SOC analyst is investigating an incident that involves a Linux system that is identifying specific sessions. Which identifier tracks an active program?
- A. runtime identification number
- B. application identification number
- C. process identification number
- D. active process identification number
Answer: C
NEW QUESTION 147
Refer to the exhibit.
Drag and drop the element name from the left onto the correct piece of the PCAP file on the right.
Answer:
Explanation:
NEW QUESTION 148
Refer to the exhibit.
Which technology generates this log?
- A. firewall
- B. NetFlow
- C. web proxy
- D. IDS
Answer: A
NEW QUESTION 149
Refer to the exhibit.
What should be interpreted from this packet capture?
- A. IP address 179.179.69/50272/192.168.122.100/80/6 is sending a packet from port 80 of IP address
192.168.122.100 that is going to port 50272 of IP address 81.179.179.69 using IP protocol 6. - B. IP address 192.168.122.100/50272/81.179.179.69/80/6 is sending a packet from port 80 of IP address
192.168.122.100 that is going to port 50272 of IP address 81.179.179.69 using IP protocol 6.7E503B693763E0113BE0CD2E4A16C9C4 - C. IP address 192.168.122.100/50272/81.179.179.69/80/6 is sending a packet from port 50272 of IP address
192.168.122.100 that is going to port 80 of IP address 81.179.179.69 using IP protocol 6. - D. IP address 179.179.69/50272/192.168.122.100/80/6 is sending a packet from port 50272 of IP address
192.168.122.100 that is going to port 80 of IP address 81.179.179.69 using IP protocol 6.
Answer: C
NEW QUESTION 150
What is the difference between vulnerability and risk?
- A. A risk is a potential threat that an exploit applies to, and a vulnerability represents the threat itself
- B. A risk is potential threat that adversaries use to infiltrate the network, and a vulnerability is an exploit
- C. A vulnerability is a sum of possible malicious entry points, and a risk represents the possibility of the unauthorized entry itself.
- D. A vulnerability represents a flaw in a security that can be exploited, and the risk is the potential damage it might cause.
Answer: D
NEW QUESTION 151
Refer to the exhibit.
What is depicted in the exhibit?
- A. Windows Event logs
- B. Apache logs
- C. IIS logs
- D. UNIX-based syslog
Answer: D
NEW QUESTION 152
......
200-201 certification guide Q&A from Training Expert SurePassExams: https://dumpsninja.surepassexams.com/200-201-exam-bootcamp.html