200-201: Understanding Cisco Cybersecurity Operati… Practice Exam
Refer to the exhibit. Which frame numbers contain a file that can be extracted through a TCP stream in Wireshark?
A7 to 21
B7 and 21
C7, 14, and 21
D14, 16, 18, and 19
Which open-source packet-capture tool is used on the Linux and Mac OS X operating systems?
ANetScout
Btcpdump
CSolarWinds
Dnetsh
The SOC team has verified a potential indicator of compromise on an endpoint. The team has narrowed the executable file type down to a new trojan family.
According to the NIST Computer Security Incident Handling Guide, what is the next step for handling this event?
APerform forensics analysis on the infected endpoint
BIsolate the infected endpoint from the network
CPrioritize incident handling based on the impact
DCollect public information on the malware behavior
Refer to the exhibit. A penetration tester performs an Nmap scan against the company server to discover potential vulnerabilities and exploit them. Which two elements can the penetration tester identify from the scan results?
Choose two
Aserver purpose and functionality
Bnumber of concurrent connections the server can handle
Cserver uptime and internal clock
Drunning services and applications
EUIDs and group identifiers
QuestionQ6
Security Concepts
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
Network Intrusion Analysis
QuestionQ8
Security Concepts
QuestionQ9
Host-Based Analysis
QuestionQ10
Security Concepts
QuestionQ11
Security Concepts
QuestionQ12
Security Concepts
QuestionQ13
Security Concepts
QuestionQ14
Host-Based Analysis
QuestionQ15
Security Concepts
QuestionQ16
Security Concepts
QuestionQ17
Security Concepts
QuestionQ18
Security Monitoring
QuestionQ19
Network Intrusion Analysis
QuestionQ20
Security Concepts
QuestionQ21
Security Concepts
QuestionQ22
Security Policies and Procedures
QuestionQ23
Network Intrusion Analysis
QuestionQ24
Security Concepts
QuestionQ25
Security Policies and Procedures
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Which CVSS metric group identifies other components affected by a successful security attack?
Ascope
Bprivileges required
Cintegrity
Dattack vendor
After a substantial influx of network traffic to externally facing devices, a security engineer investigates what appears to be a denial-of-service attack. On reviewing the packet-capture data, the engineer observes that the traffic consists of one SYN packet to each port. Which type of attack is taking place?
Atraffic fragmentation
Bport scanning
Chost profiling
DSYN flood
What distinguishes SOAR from SIEM?
ASOAR platforms are used for threat and vulnerability management, but SIEM applications are not
BSIEM applications are used for threat and vulnerability management, but SOAR platforms are not
CSOAR receives information from a single platform and delivers it to a SIEM
DSIEM receives information from a single platform and delivers it to a SOAR
Refer to the exhibit. A SOC analyst is reviewing the Auth.log logs from one of the breached systems. What is a possible reason for this event log?
Apassword cracking DoS attack on Windows endpoint
Bregular Linux log and 10.10.10.10 is legitimate host
Cbrute force attack on Linux from 10.10.10.10
Dbrute force attack on Windows from 10.10.10.10
What differentiates SIEM from SOAR?
ASIEM predicts and prevents security alerts, while SOAR checks attack patterns and applies the mitigation.
BSIEM's primary function is to collect and detect anomalies, while SOAR is more focused on security operations automation and response.
CSOAR's primary function is to collect and detect anomalies, while SIEM is more focused on security operations automation and response.
DSOAR predicts and prevents security alerts, while SIEM checks attack patterns and applies the mitigation.
What is a scareware attack?
Ainserting malicious code that causes popup windows with flashing colors
Boverwhelming a targeted website with fake traffic
Cgaining access to your computer and encrypting data stored on it
Dusing the spoofed email addresses to trick people into providing login credentials
An employee receives an email attachment from a suspicious source and chooses not to open it. Following further investigation, a security analyst determines that the file is malware. Which Cyber Kill Chain category does this event fall under?
Adelivery
Binstallation
Cexploitation
Dweaponization
Which evasion technique performs actions more slowly than usual to avoid detection?
Atiming attack
Btraffic fragmentation
Cresource exhaustion
Dtunneling
A security expert is examining a copy of the evidence: an ISO file saved in CDFS format. What type of evidence does this file represent?
ACD data copy prepared in Windows
BCD data copy prepared in Mac-based system
CCD data copy prepared in Linux system
DCD data copy prepared in Android-based system
Which activity corresponds to the weaponization phase of the Cyber Kill Chain model?
AResearch data on a specific vulnerability.
BTest and construct the appropriate malware to launch the attack.
CScan a host to find open ports and vulnerabilities.
DConstruct the appropriate malware and deliver it to the victim.
What distinguishes signature-based detection from behavior-based detection?
ASignature-based identifies behaviors that may be linked to attacks, while behavior-based has a predefined set of rules to match before an alert.
BBehavior-based identifies behaviors that may be linked to attacks, while signature-based has a predefined set of rules to match before an alert.
CBehavior-based uses a known vulnerability database, while signature-based intelligently summarizes existing data.
DSignature-based uses a known vulnerability database, while behavior-based intelligently summarizes existing data.
Which of the following describes volatile evidence?
Alogs
Bregisters and cache
Cdisk and removable drives
Dusernames
What are the two characteristics of full packet captures?
Choose two
AIdentifying network loops and collision domains.
BTroubleshooting the cause of security and performance issues.
CReassembling fragmented traffic from raw data.
DDetecting common hardware faults and identify faulty assets.
EProviding a historical record of a network transaction.
Refer to the exhibit. Which application protocol is contained in this PCAP file?
ASSH
BTCP
CTLS
DHTTP
What is the practice of granting employees only the permissions required to perform their particular role within an organization?
Aleast privilege
Bneed to know
Cintegrity validation
Ddue diligence
Which two components decrease the attack surface on an endpoint?
Choose two
Asecure boot
Bload balancing
Cincreased audit log levels
Drestricting USB ports
Efull packet captures at the endpoint
A security consultant needs to change the organization’s identity and access management model. The new approach will place responsibility with the owner, who will determine which users can access which resources. Which low-cost model must be used for this purpose?
Amandatory access control, due to low granularity
Bdiscretionary access control due to easy maintenance
Cdiscretionary access control, due to high security
Dmandatory access control, due to automatic scaling
Refer to the exhibit. What does this displayed output show?
AHTTPS ports are open on the server.
BSMB ports are closed on the server.
CFTP ports are open on the server.
DEmail ports are closed on the server.
What is one benefit of agent-based protection compared with agentless protection?
AIt lowers maintenance costs
BIt provides a centralized platform
CIt collects and detects all traffic locally
DIt manages numerous devices simultaneously
An engineer is collaborating with the compliance teams to identify the data passing through the network. During the analysis, the engineer tells the compliance team that external-perimeter data flows contain records, writings, and artwork. Internal segregated-network flows contain customer choices by gender, addresses, and product preferences by age.
The engineer must identify protected data. Which two types of data must be identified?
Community Discussion