Latest Cisco 200-201 First Attempt, Exam real Dumps Updated [Feb-2022]
Get the superior quality 200-201 Dumps Questions from Pass4SureQuiz. Nobody can stop you from getting to your dreams now. Your bright future is just a click away!
NEW QUESTION 16
Refer to the exhibit.
What is the potential threat identified in this Stealthwatch dashboard?
- A. Host 152.46.6.91 is being identified as a watchlist country for data transfer.
- B. Host 10.201.3.149 is receiving almost 19 times more data than is being sent to host 152.46.6.91.
- C. Traffic to 152.46.6.149 is being denied by an Advanced Network Control policy.
- D. Host 10.201.3.149 is sending data to 152.46.6.91 using TCP/443.
Answer: B
NEW QUESTION 17
Drag and drop the technology on the left onto the data type the technology provides on the right.
Answer:
Explanation:

NEW QUESTION 18
Which open-sourced packet capture tool uses Linux and Mac OS X operating systems?
- A. netsh
- B. NetScout
- C. SolarWinds
- D. tcpdump
Answer: D
NEW QUESTION 19
Refer to the exhibit.
An analyst received this alert from the Cisco ASA device, and numerous activity logs were produced. How should this type of evidence be categorized?
- A. indirect
- B. best
- C. corroborative
- D. circumstantial
Answer: B
NEW QUESTION 20
What does cyber attribution identity in an investigation?
- A. vulnerabilities exploited
- B. exploit of an attack
- C. threat actors of an attack
- D. cause of an attack
Answer: C
NEW QUESTION 21
Which signature impacts network traffic by causing legitimate traffic to be blocked?
- A. false positive
- B. false negative
- C. true negative
- D. true positive
Answer: A
Explanation:
Section: Network Intrusion Analysis
NEW QUESTION 22
What is the function of a command and control server?
- A. It enumerates open ports on a network device
- B. It drops secondary payload into malware
- C. It sends instruction to a compromised system
- D. It is used to regain control of the network after a compromise
Answer: C
NEW QUESTION 23
Refer to the exhibit.
What is the expected result when the "Allow subdissector to reassemble TCP streams" feature is enabled?
- A. disable TCP streams
- B. insert TCP subdissectors
- C. unfragment TCP
- D. extract a file from a packet capture
Answer: C
NEW QUESTION 24
What is a difference between inline traffic interrogation and traffic mirroring?
- A. Inline inspection acts on the original traffic data flow
- B. Traffic mirroring passes live traffic to a tool for blocking
- C. Traffic mirroring inspects live traffic for analysis and mitigation
- D. Inline traffic copies packets for analysis and security
Answer: B
Explanation:
Section: Network Intrusion Analysis
NEW QUESTION 25
When communicating via TLS, the client initiates the handshake to the server and the server responds back with its certificate for identification.
Which information is available on the server certificate?
- A. trusted subordinate CA, public key, and cipher suites
- B. trusted CA name, cipher suites, and private key
- C. server name, trusted subordinate CA, and private key
- D. server name, trusted CA, and public key
Answer: D
Explanation:
Section: Security Monitoring
NEW QUESTION 26
Why is encryption challenging to security monitoring?
- A. Encryption is used by threat actors as a method of evasion and obfuscation.
- B. Encryption introduces larger packet sizes to analyze and store.
- C. Encryption introduces additional processing requirements by the CPU.
- D. Encryption analysis is used by attackers to monitor VPN tunnels.
Answer: A
NEW QUESTION 27
Drag and drop the security concept on the left onto the example of that concept on the right.
Answer:
Explanation:

NEW QUESTION 28
What is the impact of false positive alerts on business compared to true positive?
- A. True positives affect security as no alarm is raised when an attack has taken place, resulting in a potential breach.
- B. False positive alerts are blocked by mistake as potential attacks affecting application availability.
- C. True positive alerts are blocked by mistake as potential attacks affecting application availability.
- D. False positives affect security as no alarm is raised when an attack has taken place, resulting in a potential breach.
Answer: D
NEW QUESTION 29
Refer to the exhibit.
What is occurring in this network?
- A. ARP cache poisoning
- B. DNS cache poisoning
- C. MAC flooding attack
- D. MAC address table overflow
Answer: A
NEW QUESTION 30
Refer to the exhibit.
What does the output indicate about the server with the IP address 172.18.104.139?
- A. running processes of the server
- B. open ports of a web server
- C. open ports of an email server
- D. open port of an FTP server
Answer: C
NEW QUESTION 31
What is a difference between SOAR and SIEM?
- A. SIEM receives information from a single platform and delivers it to a SOAR
- B. SOAR receives information from a single platform and delivers it to a SIEM
- C. SOAR platforms are used for threat and vulnerability management, but SIEM applications are not
- D. SIEM applications are used for threat and vulnerability management, but SOAR platforms are not
Answer: C
Explanation:
Section: Security Concepts
Explanation
NEW QUESTION 32
Which category relates to improper use or disclosure of PII data?
- A. compliance
- B. legal
- C. regulated
- D. contractual
Answer: C
Explanation:
Section: Security Policies and Procedures
NEW QUESTION 33
What is the practice of giving an employee access to only the resources needed to accomplish their job?
- A. organizational separation
- B. separation of duties
- C. need to know principle
- D. principle of least privilege
Answer: D
NEW QUESTION 34 
Refer to the exhibit. What does the output indicate about the server with the IP address 172.18.104.139?
- A. running processes of the server
- B. open ports of a web server
- C. open ports of an email server
- D. open port of an FTP server
Answer: C
Explanation:
Section: Security Monitoring
NEW QUESTION 35
While viewing packet capture data, an analyst sees that one IP is sending and receiving traffic for multiple devices by modifying the IP header.
Which technology makes this behavior possible?
- A. NAT
- B. encapsulation
- C. tunneling
- D. TOR
Answer: A
NEW QUESTION 36
An engineer is investigating a case of the unauthorized usage of the "Tcpdump" tool. The analysis revealed that a malicious insider attempted to sniff traffic on a specific interface. What type of information did the malicious insider attempt to obtain?
- A. tagged ports being used on the network
- B. all information and data within the datagram
- C. all firewall alerts and resulting mitigations
- D. tagged protocols being used on the network
Answer: A
NEW QUESTION 37
An analyst received a ticket regarding a degraded processing capability for one of the HR department's servers. On the same day, an engineer noticed a disabled antivirus software and was not able to determine when or why it occurred. According to the NIST Incident Handling Guide, what is the next phase of this investigation?
- A. Detection
- B. Analysis
- C. Eradication
- D. Recovery
Answer: A
NEW QUESTION 38
......
Cisco Practice Test Engine with 200-201 Questions: https://drive.google.com/open?id=1TUhaU7Kuxh_CFBFHLuAuUd6meOqMy8iu
Guaranteed Success with Valid Cisco 200-201 Dumps: https://www.pass4surequiz.com/200-201-exam-quiz.html