Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the Cisco CyberOps Associate 200-201 Questions and answers with ValidTests

Exam 200-201 All Questions
Exam 200-201 Premium Access

View all detail and faqs for the 200-201 exam

Viewing page 14 out of 15 pages
Viewing questions 131-140 out of questions
Questions # 131:

Which attack method intercepts traffic on a switched network?

Options:

A.

denial of service

B.

ARP cache poisoning

C.

DHCP snooping

D.

command and control

Questions # 132:

A security engineer notices confidential data being exfiltrated to a domain "Ranso4134-mware31-895" address that is attributed to a known advanced persistent threat group The engineer discovers that the activity is part of a real attack and not a network misconfiguration. Which category does this event fall under as defined in the Cyber Kill Chain?

Options:

A.

reconnaissance

B.

delivery

C.

action on objectives

D.

weaponization

Questions # 133:

What describes the vulnerability management process?

Options:

A.

securely observe and supervise devices that access sensitive enterprise data

B.

systems engineering process for establishing and preserving consistency of a product's performance

C.

involves the deployment of hotfixes and patches that are released from time to time

D.

cyclical approach of identifying classifying and mitigating software vulnerabilities

Questions # 134:

Which metric should be used when evaluating the effectiveness and scope of a Security Operations Center?

Options:

A.

The average time the SOC takes to register and assign the incident.

B.

The total incident escalations per week.

C.

The average time the SOC takes to detect and resolve the incident.

D.

The total incident escalations per month.

Questions # 135:

Question # 135

Refer to the exhibit. An employee received an email from an unknown sender with an attachment and reported it as a phishing attempt. An engineer uploaded the file to Cuckoo for further analysis. What should an engineer interpret from the provided Cuckoo report?

Options:

A.

Win32.polip.a.exe is an executable file and should be flagged as malicious.

B.

The file is clean and does not represent a risk.

C.

Cuckoo cleaned the malicious file and prepared it for usage.

D.

MD5 of the file was not identified as malicious.

Questions # 136:

What are indicators of attack?

Options:

A.

large numbers of requests for the same file

B.

multiple tog ins from different regions

C.

swells in database read volume

D.

suspicious registry or system file changes

Questions # 137:

What is the difference between the ACK flag and the RST flag in the NetFlow log session?

Options:

A.

The RST flag confirms the beginning of the TCP connection, and the ACK flag responds when the data for the payload is complete

B.

The ACK flag confirms the beginning of the TCP connection, and the RST flag responds when the data for the payload is complete

C.

The RST flag confirms the receipt of the prior segment, and the ACK flag allows for the spontaneous termination of a connection

D.

The ACK flag confirms the receipt of the prior segment, and the RST flag allows for the spontaneous termination of a connection

Questions # 138:

An investigator is examining a copy of an ISO file that is stored in CDFS format. What type of evidence is this file?

Options:

A.

data from a CD copied using Mac-based system

B.

data from a CD copied using Linux system

C.

data from a DVD copied using Windows system

D.

data from a CD copied using Windows

Questions # 139:

According to CVSS, what is attack complexity?

Options:

A.

existing exploits available in the wild exploiting the vulnerability

B.

existing circumstances beyond the attacker's control to exploit the vulnerability

C.

number of actions an attacker should perform to exploit the vulnerability

D.

number of patches available for certain attack mitigation and how complex the workarounds are

Questions # 140:

Which regular expression is needed to capture the IP address 192.168.20.232?

Options:

A.

^(?:[0-9]{1,3}\.){3}[0-9]{1,3}

B.

^(?:[0-9]f1,3}\.){1,4}

C.

^(?:[0-9]{1,3}\.)'

D.

^([0-9]-{3})

Viewing page 14 out of 15 pages
Viewing questions 131-140 out of questions