Latest Cisco 200-201 First Attempt, Exam real Dumps Updated [Feb-2022]
Get the superior quality 200-201 Dumps Questions from Actual4test. Nobody can stop you from getting to your dreams now. Your bright future is just a click away!
NEW QUESTION 48
A SOC analyst is investigating an incident that involves a Linux system that is identifying specific sessions. Which identifier tracks an active program?
- A. application identification number
- B. runtime identification number
- C. active process identification number
- D. process identification number
Answer: D
NEW QUESTION 49
Which type of evidence supports a theory or an assumption that results from initial evidence?
- A. corroborative
- B. indirect
- C. best
- D. probabilistic
Answer: A
Explanation:
Explanation
NEW QUESTION 50
Which type of data collection requires the largest amount of storage space?
- A. transaction data
- B. full packet capture
- C. session data
- D. alert data
Answer: B
NEW QUESTION 51
Refer to the exhibit.
Which packet contains a file that is extractable within Wireshark?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: C
NEW QUESTION 52
How does an SSL certificate impact security between the client and the server?
- A. by enabling an authorized channel between the client and the server
- B. by creating an integrated channel between the client and the server
- C. by creating an encrypted channel between the client and the server
Section: (none)
Explanation - D. by enabling an authenticated channel between the client and the server
Answer: C
NEW QUESTION 53 
Refer to the exhibit. What is the expected result when the "Allow subdissector to reassemble TCP streams" feature is enabled?
- A. disable TCP streams
- B. unfragment TCP
- C. insert TCP subdissectors
- D. extract a file from a packet capture
Answer: B
Explanation:
Section: Network Intrusion Analysis
NEW QUESTION 54
Which system monitors local system operation and local network access for violations of a security policy?
- A. host-based intrusion detection
- B. systems-based sandboxing
- C. antivirus
- D. host-based firewall
Answer: D
Explanation:
Section: Host-Based Analysis
NEW QUESTION 55
Refer to the exhibit.
What is occurring in this network traffic?
- A. flood of ACK packets coming from a single source IP to multiple destination IPs
- B. flood of SYN packets coming from a single source IP to a single destination IP
- C. high rate of SYN packets being sent from a multiple source towards a single destination IP
- D. high rate of SYN packets being sent from a single source IP towards multiple destination IPs
Answer: B
NEW QUESTION 56
A security engineer deploys an enterprise-wide host/endpoint technology for all of the company's corporate PCs. Management requests the engineer to block a selected set of applications on all PCs.
Which technology should be used to accomplish this task?
- A. network NGFW
- B. host-based IDS
- C. application whitelisting/blacklisting
- D. antivirus/antispyware software
Answer: C
NEW QUESTION 57
Refer to the exhibit.
What is the expected result when the "Allow subdissector to reassemble TCP streams" feature is enabled?
- A. disable TCP streams
- B. unfragment TCP
- C. insert TCP subdissectors
- D. extract a file from a packet capture
Answer: B
NEW QUESTION 58
An employee reports that someone has logged into their system and made unapproved changes, files are out of order, and several documents have been placed in the recycle bin. The security specialist reviewed the system logs, found nothing suspicious, and was not able to determine what occurred. The software is up to date; there are no alerts from antivirus and no failed login attempts. What is causing the lack of data visibility needed to detect the attack?
- A. The threat actor used an unknown vulnerability of the operating system that went undetected.
- B. The threat actor used the teardrop technique to confuse and crash login services.
- C. The threat actor gained access to the system by known credentials.
- D. The threat actor used a dictionary-based password attack to obtain credentials.
Answer: C
NEW QUESTION 59 
Refer to the exhibit. Which packet contains a file that is extractable within Wireshark?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: C
Explanation:
Explanation
NEW QUESTION 60
Refer to the exhibit.
Which packet contains a file that is extractable within Wireshark?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: C
NEW QUESTION 61
Refer to the exhibit.
An engineer is analyzing this Cuckoo Sandbox report for a PDF file that has been downloaded from an email. What is the state of this file?
- A. The file has an embedded executable and was matched by PEiD threat signatures for further analysis.
- B. The file was matched by PEiD threat signatures but no suspicious features are identified since the signature list is up to date.
- C. The file has an embedded Windows 32 executable and the Yara field lists suspicious features for further analysis.
- D. The file has an embedded non-Windows executable but no suspicious features are identified.
Answer: C
NEW QUESTION 62 
Refer to the exhibit. What should be interpreted from this packet capture?
- A. IP address 192.168.122.100/50272/81.179.179.69/80/6 is sending a packet from port 80 of IP address
192.168.122.100 that is going to port 50272 of IP address 81.179.179.69 using IP protocol 6. - B. IP address 192.168.122.100/50272/81.179.179.69/80/6 is sending a packet from port 50272 of IP address
192.168.122.100 that is going to port 80 of IP address 81.179.179.69 using IP protocol 6. - C. IP address 179.179.69/50272/192.168.122.100/80/6 is sending a packet from port 80 of IP address
192.168.122.100 that is going to port 50272 of IP address 81.179.179.69 using IP protocol 6. - D. IP address 179.179.69/50272/192.168.122.100/80/6 is sending a packet from port 50272 of IP address
192.168.122.100 that is going to port 80 of IP address 81.179.179.69 using IP protocol 6.
Answer: B
Explanation:
Section: Security Monitoring
NEW QUESTION 63
What is the impact of false positive alerts on business compared to true positive?
- A. True positives affect security as no alarm is raised when an attack has taken place, resulting in a potential breach.
- B. True positive alerts are blocked by mistake as potential attacks affecting application availability.
- C. False positive alerts are blocked by mistake as potential attacks affecting application availability.
- D. False positives affect security as no alarm is raised when an attack has taken place, resulting in a potential breach.
Answer: D
NEW QUESTION 64
Which two elements are used for profiling a network? (Choose two.)
- A. running processes
- B. session duration
- C. listening ports
- D. OS fingerprint
- E. total throughput
Answer: C,D
Explanation:
Section: Security Policies and Procedures
Explanation
NEW QUESTION 65
Which principle is being followed when an analyst gathers information relevant to a security incident to determine the appropriate course of action?
- A. decision making
- B. data mining
- C. rapid response
- D. due diligence
Answer: C
NEW QUESTION 66
Which security technology allows only a set of pre-approved applications to run on a system?
- A. application-level whitelisting
- B. host-based IPS
- C. application-level blacklisting
- D. antivirus
Answer: A
Explanation:
Section: Host-Based Analysis
NEW QUESTION 67
Which data format is the most efficient to build a baseline of traffic seen over an extended period of time?
- A. syslog messages
- B. NetFlow
- C. firewall event logs
- D. full packet capture
Answer: B
Explanation:
Section: Security Monitoring
NEW QUESTION 68
......
Cisco Practice Test Engine with 200-201 Questions: https://drive.google.com/open?id=1QxduEkJ_mHhppCWYQKV7KXLjUUVddsHR
Guaranteed Success with Valid Cisco 200-201 Dumps: https://www.actual4test.com/200-201_examcollection.html