Latest Feb-2022 Cisco 200-201 Dumps Updated 182 Questions [Q74-Q98]

Share

Latest Feb-2022 Cisco 200-201 Dumps Updated 182 Questions

PDF Download Free of 200-201 Valid Practice Test Questions


Cisco 200-201 Exam Topics:

SectionWeightObjectives
Security Monitoring25%1.Compare attack surface and vulnerability
2.Identify the types of data provided by these technologies
  • TCP dump
  • NetFlow
  • Next-gen firewall
  • Traditional stateful firewall
  • Application visibility and control
  • Web content filtering
  • Email content filtering

3.Describe the impact of these technologies on data visibility

  • Access control list
  • NAT/PAT
  • Tunneling
  • TOR
  • Encryption
  • P2P
  • Encapsulation
  • Load balancing

4.Describe the uses of these data types in security monitoring

  • Full packet capture
  • Session data
  • Transaction data
  • Statistical data
  • Metadata
  • Alert data

5.Describe network attacks, such as protocol-based, denial of service, distributed denial of service, and man-in-the-middle
6.Describe web application attacks, such as SQL injection, command injections, and cross-site scripting
7.Describe social engineering attacks
8.Describe endpoint-based attacks, such as buffer overflows, command and control (C2), malware, and ransomware
9.Describe evasion and obfuscation techniques, such as tunneling, encryption, and proxies
10.Describe the impact of certificates on security (includes PKI, public/private crossing the network, asymmetric/symmetric)
11.Identify the certificate components in a given scenario

  • Cipher-suite
  • X.509 certificates
  • Key exchange
  • Protocol version
  • PKCS
Network Intrusion Analysis20%1.Map the provided events to source technologies
  • IDS/IPS
  • Firewall
  • Network application control
  • Proxy logs
  • Antivirus
  • Transaction data (NetFlow)

2.Compare impact and no impact for these items

  • False positive
  • False negative
  • True positive
  • True negative
  • Benign

3.Compare deep packet inspection with packet filtering and stateful firewall operation
4.Compare inline traffic interrogation and taps or traffic monitoring
5.Compare the characteristics of data obtained from taps or traffic monitoring and transactional data (NetFlow) in the analysis of network traffic
6.Extract files from a TCP stream when given a PCAP file and Wireshark
7.Identify key elements in an intrusion from a given PCAP file

  • Source address
  • Destination address
  • Source port
  • Destination port
  • Protocols
  • Payloads

8.Interpret the fields in protocol headers as related to intrusion analysis

  • Ethernet frame
  • IPv4
  • IPv6
  • TCP
  • UDP
  • ICMP
  • DNS
  • SMTP/POP3/IMAP
  • HTTP/HTTPS/HTTP2
  • ARP

9.Interpret common artifact elements from an event to identify an alert

  • IP address (source / destination)
  • Client and server port identity
  • Process (file or registry)
  • System (API calls)
  • Hashes
  • URI / URL

10.Interpret basic regular expressions

Security Concepts20%1. Describe the CIA triad
2. Compare security deployments
  • Network, endpoint, and application security systems
  • Agentless and agent-based protections
  • Legacy antivirus and antimalware
  • SIEM, SOAR, and log management

3. Describe security terms

  • Threat intelligence (TI)
  • Threat hunting
  • Malware analysis
  • Threat actor
  • Run book automation (RBA)
  • Reverse engineering
  • Sliding window anomaly detection
  • Principle of least privilege
  • Zero trust
  • Threat intelligence platform (TIP)

4. Compare security concepts

  • Risk (risk scoring/risk weighting, risk reduction, risk assessment)
  • Threat
  • Vulnerability
  • Exploit

5.Describe the principles of the defense-in-depth strategy
6.Compare access control models

  • Discretionary access control
  • Mandatory access control
  • Nondiscretionary access control
  • Authentication, authorization, accounting
  • Rule-based access control
  • Time-based access control
  • Role-based access control

7.Describe terms as defined in CVSS

  • Attack vector
  • Attack complexity
  • Privileges required
  • User interaction
  • Scope

8.Identify the challenges of data visibility (network, host, and cloud) in detection
9.Identify potential data loss from provided traffic profiles
10.Interpret the 5-tuple approach to isolate a compromised host in a grouped set of logs
11.Compare rule-based detection vs. behavioral and statistical detection



Exam Topics

The Cisco 200-201 exam will validate your skills and knowledge of security monitoring, security concepts, security policies & procedures, host-based analysis, and network intrusion analysis. All in all, its content comes with 5 topics that are listed as follows:

Security Concepts

This domain makes up 20% of the exam content and measures the applicants’ abilities to perform the following tasks:

  • Describe the 5-tuple method to separate a compromised host in a grouped set of logs.
  • Classify the difficulties of data visibility in detention;
  • Compare rule-based detection vs. behavioral and statistical detection;
  • Analyze security deployments – It includes the agent-based and agentless protections as well as network, endpoint, and application security systems. You should also know about log management, SOAR & SIEM, and Legacy antivirus & antimalware;
  • Define the CIA triad;
  • Understand CVSS – You need to have knowledge of the attack vector, privileges required, scope, and user interaction;
  • Define security terms – The potential candidates have to know about hunting, actor & threat intelligence, and TI platform, malware analysis, run book cybernation, as well as sliding window exception detection;
  • Determine the possible data loss from the available traffic profiles;
  • Compare various security concepts – As for this one, it covers the details of risk scoring, assessment, and reduction as well as vulnerability, exploit, and threat;

 

NEW QUESTION 74
Refer to the exhibit.

Which type of log is displayed?

  • A. IDS
  • B. NetFlow
  • C. proxy
  • D. sys

Answer: D

 

NEW QUESTION 75
Refer to the exhibit.

Which application protocol is in this PCAP file?

  • A. SSH
  • B. HTTP
  • C. TLS
  • D. TCP

Answer: D

 

NEW QUESTION 76
Drag and drop the technology on the left onto the data type the technology provides on the right.

Answer:

Explanation:

 

NEW QUESTION 77
Which security principle requires more than one person is required to perform a critical task?

  • A. need to know
  • B. separation of duties
  • C. least privilege
  • D. due diligence

Answer: B

Explanation:
Section: Security Concepts

 

NEW QUESTION 78
Refer to the exhibit.

What does the message indicate?

  • A. a successful access attempt was made to retrieve the root of the website
  • B. an access attempt was made from the Mosaic web browser
  • C. a successful access attempt was made to retrieve the password file
  • D. a denied access attempt was made to retrieve the password file

Answer: A

 

NEW QUESTION 79
Refer to the exhibit.

What is shown in this PCAP file?

  • A. The User-Agent is Mozilla/5.0.
  • B. The protocol is TCP.
  • C. The HTTP GET is encoded.
  • D. Timestamps are indicated with error.

Answer: D

 

NEW QUESTION 80
Refer to the exhibit.

Which packet contains a file that is extractable within Wireshark?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: C

 

NEW QUESTION 81

An analyst is investigating a host in the network that appears to be communicating to a command and control server on the Internet. After collecting this packet capture the analyst cannot determine the technique and payload used for the communication.
Which obfuscation technique is the attacker using?

  • A. SHA-256 hashing
  • B. transport layer security encryption
  • C. Base64 encoding
  • D. ROT13 encryption

Answer: B

 

NEW QUESTION 82

Refer to the exhibit. What is the expected result when the "Allow subdissector to reassemble TCP streams" feature is enabled?

  • A. disable TCP streams
  • B. unfragment TCP
  • C. insert TCP subdissectors
  • D. extract a file from a packet capture

Answer: B

 

NEW QUESTION 83
An engineer needs to fetch logs from a proxy server and generate actual events according to the data received. Which technology should the engineer use to accomplish this task?

  • A. Firepower
  • B. Email Security Appliance
  • C. Web Security Appliance
  • D. Stealthwatch

Answer: C

 

NEW QUESTION 84
An engineer is addressing a connectivity issue between two servers where the remote server is unable to establish a successful session. Initial checks show that the remote server is not receiving an SYN-ACK while establishing a session by sending the first SYN. What is causing this issue?

  • A. incorrect UDP handshake
  • B. incorrect OSI configuration
  • C. incorrect TCP handshake
  • D. incorrect snaplen configuration

Answer: C

 

NEW QUESTION 85
What is the difference between a threat and a risk?

  • A. Threat represents a potential danger that could take advantage of a weakness in a system
  • B. Threat represents a state of being exposed to an attack or a compromise either physically or logically
  • C. Risk represents the nonintentional interaction with uncertainty in the system
  • D. Risk represents the known and identified loss or danger in the system

Answer: A

 

NEW QUESTION 86
What is a benefit of agent-based protection when compared to agentless protection?

  • A. It provides a centralized platform
  • B. It lowers maintenance costs
  • C. It manages numerous devices simultaneously
  • D. It collects and detects all traffic locally

Answer: A

 

NEW QUESTION 87
Refer to the exhibit.

What is the potential threat identified in this Stealthwatch dashboard?

  • A. A host on the network is sending a DDoS attack to another inside host.
  • B. A policy violation is active for host 10.10.101.24.
  • C. There are two active data exfiltration alerts.
  • D. A policy violation is active for host 10.201.3.149.

Answer: C

 

NEW QUESTION 88
Which type of evidence supports a theory or an assumption that results from initial evidence?

  • A. corroborative
  • B. indirect
  • C. best
  • D. probabilistic

Answer: A

 

NEW QUESTION 89
What is personally identifiable information that must be safeguarded from unauthorized access?

  • A. gender
  • B. date of birth
  • C. zip code
  • D. driver's license number

Answer: D

Explanation:
Section: Security Policies and Procedures

 

NEW QUESTION 90
W[^t is vulnerability management?

  • A. A security practice focused on clarifying and narrowing intrusion points.
  • B. A process to recover from service interruptions and restore business-critical applications
  • C. A process to identify and remediate existing weaknesses.
  • D. A security practice of performing actions rather than acknowledging the threats.

Answer: C

 

NEW QUESTION 91
The SOC team has confirmed a potential indicator of compromise on an endpoint. The team has narrowed the executable file's type to a new trojan family. According to the NIST Computer Security Incident Handling Guide, what is the next step in handling this event?

  • A. Prioritize incident handling based on the impact.
  • B. Isolate the infected endpoint from the network.
  • C. Collect public information on the malware behavior.
  • D. Perform forensics analysis on the infected endpoint.

Answer: C

 

NEW QUESTION 92
What is the difference between mandatory access control (MAC) and discretionary access control (DAC)?

  • A. MAC is controlled by the discretion of the owner and DAC is controlled by an administrator
  • B. DAC is the strictest of all levels of control and MAC is object-based access
  • C. MAC is the strictest of all levels of control and DAC is object-based access
  • D. DAC is controlled by the operating system and MAC is controlled by an administrator

Answer: C

 

NEW QUESTION 93

Refer to the exhibit. Which event is occurring?

  • A. A binary is being submitted to run on VM cuckoo1
  • B. A binary on VM cuckoo1 is being submitted for evaluation
  • C. A URL is being evaluated to see if it has a malicious binary
  • D. A binary named "submit" is running on VM cuckoo1.

Answer: B

 

NEW QUESTION 94
Which two elements are used for profiling a network? (Choose two.)

  • A. running processes
  • B. session duration
  • C. listening ports
  • D. OS fingerprint
  • E. total throughput

Answer: C,D

Explanation:
Section: Security Policies and Procedures
Explanation

 

NEW QUESTION 95
What is the difference between a threat and a risk?

  • A. Threat represents a potential danger that could take advantage of a weakness in a system
  • B. Risk represents the nonintentional interaction with uncertainty in the system
  • C. Risk represents the known and identified loss or danger in the system
  • D. Threat represents a state of being exposed to an attack or a compromise, either physically or logically.

Answer: A

Explanation:
Explanation
A threat is any potential danger to an asset. If a vulnerability exists but has not yet been exploited-or, more importantly, it is not yet publicly known-the threat is latent and not yet realized.

 

NEW QUESTION 96
Which two elements are assets in the role of attribution in an investigation? (Choose two.)

  • A. context
  • B. session
  • C. firewall logs
  • D. laptop
  • E. threat actor

Answer: A,E

Explanation:
Section: Security Policies and Procedures

 

NEW QUESTION 97
Which system monitors local system operation and local network access for violations of a security policy?

  • A. host-based firewall
  • B. host-based intrusion detection
  • C. systems-based sandboxing
  • D. antivirus

Answer: B

Explanation:
Explanation
HIDS is capable of monitoring the internals of a computing system as well as the network packets on its network interfaces. Host-based firewall is a piece of software running on a single Host that can restrict incoming and outgoing Network activity for that host only.

 

NEW QUESTION 98
......

200-201 Test Engine files, 200-201 Dumps PDF: https://www.testkingfree.com/Cisco/200-201-practice-exam-dumps.html

Latest Cisco 200-201 PDF and Dumps (2022) Free Exam Questions Answers: https://drive.google.com/open?id=13xE-DggEcGKKQhqT6aEGnMMuqABBXWh5