Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the Cisco CyberOps Professional 350-201 Questions and answers with ValidTests

Exam 350-201 All Questions
Exam 350-201 Premium Access

View all detail and faqs for the 350-201 exam

Viewing page 2 out of 5 pages
Viewing questions 11-20 out of questions
Questions # 11:

Refer to the exhibit.

Question # 11

At which stage of the threat kill chain is an attacker, based on these URIs of inbound web requests from known malicious Internet scanners?

Options:

A.

exploitation

B.

actions on objectives

C.

delivery

D.

reconnaissance

Expert Solution
Questions # 12:

An engineer is investigating several cases of increased incoming spam emails and suspicious emails from the HR and service departments. While checking the event sources, the website monitoring tool showed several web scraping alerts overnight. Which type of compromise is indicated?

Options:

A.

phishing

B.

dumpster diving

C.

social engineering

D.

privilege escalation

Expert Solution
Questions # 13:

An engineer received an alert of a zero-day vulnerability affecting desktop phones through which an attacker sends a crafted packet to a device, resets the credentials, makes the device unavailable, and allows a default

administrator account login. Which step should an engineer take after receiving this alert?

Options:

A.

Initiate a triage meeting to acknowledge the vulnerability and its potential impact

B.

Determine company usage of the affected products

C.

Search for a patch to install from the vendor

D.

Implement restrictions within the VoIP VLANS

Expert Solution
Questions # 14:

A SOC team is investigating a recent, targeted social engineering attack on multiple employees. Cross- correlated log analysis revealed that two hours before the attack, multiple assets received requests on TCP port 79. Which action should be taken by the SOC team to mitigate this attack?

Options:

A.

Disable BIND forwarding from the DNS server to avoid reconnaissance.

B.

Disable affected assets and isolate them for further investigation.

C.

Configure affected devices to disable NETRJS protocol.

D.

Configure affected devices to disable the Finger service.

Expert Solution
Questions # 15:

An organization had several cyberattacks over the last 6 months and has tasked an engineer with looking for patterns or trends that will help the organization anticipate future attacks and mitigate them. Which data analytic technique should the engineer use to accomplish this task?

Options:

A.

diagnostic

B.

qualitative

C.

predictive

D.

statistical

Expert Solution
Questions # 16:

Refer to the exhibit.

Question # 16

Where is the MIME type that should be followed indicated?

Options:

A.

x-test-debug

B.

strict-transport-security

C.

x-xss-protection

D.

x-content-type-options

Expert Solution
Questions # 17:

Refer to the exhibit.

Question # 17

Which asset has the highest risk value?

Options:

A.

servers

B.

website

C.

payment process

D.

secretary workstation

Expert Solution
Questions # 18:

An organization suffered a security breach in which the attacker exploited a Netlogon Remote Protocol vulnerability for further privilege escalation. Which two actions should the incident response team take to

prevent this type of attack from reoccurring? (Choose two.)

Options:

A.

Implement a patch management process.

B.

Scan the company server files for known viruses.

C.

Apply existing patches to the company servers.

D.

Automate antivirus scans of the company servers.

E.

Define roles and responsibilities in the incident response playbook.

Expert Solution
Questions # 19:

Refer to the exhibit.

Question # 19

For IP 192.168.1.209, what are the risk level, activity, and next step?

Options:

A.

high risk level, anomalous periodic communication, quarantine with antivirus

B.

critical risk level, malicious server IP, run in a sandboxed environment

C.

critical risk level, data exfiltration, isolate the device

D.

high risk level, malicious host, investigate further

Expert Solution
Questions # 20:

A security analyst receives an escalation regarding an unidentified connection on the Accounting A1 server within a monitored zone. The analyst pulls the logs and discovers that a Powershell process and a WMI tool process were started on the server after the connection was established and that a PE format file was created in the system directory. What is the next step the analyst should take?

Options:

A.

Isolate the server and perform forensic analysis of the file to determine the type and vector of a possible attack

B.

Identify the server owner through the CMDB and contact the owner to determine if these were planned and identifiable activities

C.

Review the server backup and identify server content and data criticality to assess the intrusion risk

D.

Perform behavioral analysis of the processes on an isolated workstation and perform cleaning procedures if the file is malicious

Expert Solution
Viewing page 2 out of 5 pages
Viewing questions 11-20 out of questions