Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the Cisco CyberOps Associate 200-201 Questions and answers with ValidTests

Exam 200-201 All Questions
Exam 200-201 Premium Access

View all detail and faqs for the 200-201 exam

Viewing page 7 out of 15 pages
Viewing questions 61-70 out of questions
Questions # 61:

Which event artifact is used to identify HTTP GET requests for a specific file?

Options:

A.

destination IP address

B.

TCP ACK

C.

HTTP status code

D.

URI

Expert Solution
Questions # 62:

What is the principle of defense-in-depth?

Options:

A.

Agentless and agent-based protection for security are used.

B.

Several distinct protective layers are involved.

C.

Access control models are involved.

D.

Authentication, authorization, and accounting mechanisms are used.

Expert Solution
Questions # 63:

Drag and drop the definition from the left onto the phase on the right to classify intrusion events according to the Cyber Kill Chain model.

Options:

Expert Solution
Questions # 64:

Refer to the exhibit.

What information is depicted?

Options:

A.

IIS data

B.

NetFlow data

C.

network discovery event

D.

IPS event data

Expert Solution
Questions # 65:

Which principle is being followed when an analyst gathers information relevant to a security incident to determine the appropriate course of action?

Options:

A.

decision making

B.

rapid response

C.

data mining

D.

due diligence

Expert Solution
Questions # 66:

Refer to exhibit.

Question # 66

An engineer is Investigating an Intrusion and Is analyzing the pcap file. Which two key elements must an engineer consider? (Choose two.)

Options:

A.

Variable "info" field and unchanging sequence number

B.

High volume oi SYN packets with very little variance in lime

C.

identical length of 120 and window size (64)

D.

SYN packets acknowledged from several source IP addresses

E.

same source IP address with a destination port 80

Expert Solution
Questions # 67:

Refer to the exhibit.

Which application protocol is in this PCAP file?

Options:

A.

SSH

B.

TCP

C.

TLS

D.

HTTP

Expert Solution
Questions # 68:

Which attack method is being used when an attacker tries to compromise a network with an authentication system that uses only 4-digit numeric passwords and no username?

Options:

A.

SQL injection

B.

dictionary

C.

replay

D.

cross-site scripting

Expert Solution
Questions # 69:

Refer to the exhibit.

Which stakeholders must be involved when a company workstation is compromised?

Options:

A.

Employee 1 Employee 2, Employee 3, Employee 4, Employee 5, Employee 7

B.

Employee 1, Employee 2, Employee 4, Employee 5

C.

Employee 4, Employee 6, Employee 7

D.

Employee 2, Employee 3, Employee 4, Employee 5

Expert Solution
Questions # 70:

A security engineer notices confidential data being exfiltrated to a domain "Ranso4134-mware31-895" address that is attributed to a known advanced persistent threat group The engineer discovers that the activity is part of a real attack and not a network misconfiguration. Which category does this event fall under as defined in the Cyber Kill Chain?

Options:

A.

reconnaissance

B.

delivery

C.

action on objectives

D.

weaponization

Expert Solution
Viewing page 7 out of 15 pages
Viewing questions 61-70 out of questions