200-201 PDF Exam Material 2022 Realistic 200-201 Dumps Questions [Q50-Q70]

Share

200-201 PDF Exam Material 2022 Realistic 200-201 Dumps Questions

Updated Cisco 200-201 Dumps – PDF & Online Engine


Certification Details: Cisco Certified CyberOps Associate

The recently updated Cisco Certified CyberOps Associate curriculum verifies the everyday knowledge and technical skills that you need to identify and mitigate security threats as part of a Security Operations Center (SOC). In addition, it opens your path to a career in cybersecurity. Cisco doesn’t list any mandatory prerequisites for attaining the CyberOps Associate designation but it’s always advisable to master the exam objectives before focusing on the certification path.


Understanding functional and technical aspects of Cisco Cybersecurity Operations Fundamentals v1.0 (200-201 CBROPS) Security Policies and Procedures

The following will be discussed in CISCO 200-201 exam dumps:

  • Applications
  • Patch management
  • Post-incident analysis (lessons learned)
  • Describe the elements in an incident response plan as stated in NIST.SP800-61
  • Describe management concepts
  • Detection and analysis
  • Data preservation
  • Containment, eradication, and recovery
  • Detection and analysis
  • Ports used
  • Asset management
  • Data integrity
  • Preparation
  • Logged in users/service accounts
  • Intellectual property
  • Volatile data collection
  • PII
  • Listening ports
  • Containment, eradication, and recovery
  • Running processes
  • Apply the incident handling process (such as NIST.SP800-61) to an event
  • Identify these elements used for server profiling
  • Conduct security incident investigations.
  • PHI
  • Identify the common attack vectors.
  • Identify these elements used for network profiling
  • Total throughput
  • Evidence collection order
  • Explain the use of a typical playbook in the SOC.
  • Map elements to these steps of analysis based on the NIST.SP800-61
  • Classify intrusion events into categories as defined by security models, such as Cyber Kill Chain Model and Diamond Model of Intrusion
  • PSI
  • Mobile device management
  • Post-incident analysis (lessons learned)
  • Explain the use of a workflow management system and automation to improve the effectiveness of the SOC.
  • Preparation
  • Identify patterns of suspicious behaviors.
  • Configuration management
  • Identify malicious activities.

 

NEW QUESTION 50
Which are two denial-of-service attacks? (Choose two.)

  • A. code-red
  • B. ping of death
  • C. TCP connections
  • D. man-in-the-middle
  • E. UDP flooding

Answer: B,E

 

NEW QUESTION 51

Refer to the exhibit. What is the expected result when the "Allow subdissector to reassemble TCP streams" feature is enabled?

  • A. unfragment TCP
  • B. extract a file from a packet capture
  • C. insert TCP subdissectors
  • D. disable TCP streams

Answer: A

 

NEW QUESTION 52
Which type of attack occurs when an attacker is successful in eavesdropping on a conversation between two IP phones?

  • A. dictionary
  • B. known-plaintext
  • C. man-in-the-middle
  • D. replay

Answer: C

 

NEW QUESTION 53
What is the difference between an attack vector and attack surface?

  • A. An attack vector identifies components that can be exploited; and an attack surface identifies the potential path an attack can take to penetrate the network.
  • B. An attack surface identifies vulnerabilities that require user input or validation; and an attack vector identifies vulnerabilities that are independent of user actions.
  • C. An attack surface recognizes which network parts are vulnerable to an attack; and an attack vector identifies which attacks are possible with these vulnerabilities.
  • D. An attack vector identifies the potential outcomes of an attack; and an attack surface launches an attack using several methods against the identified vulnerabilities.

Answer: C

Explanation:
Section: Security Concepts

 

NEW QUESTION 54
Refer to the exhibit.

What does this output indicate?

  • A. Email ports are closed on the server.
  • B. SMB ports are closed on the server.
  • C. FTP ports are open on the server.
  • D. HTTPS ports are open on the server.

Answer: A

 

NEW QUESTION 55
What is the difference between statistical detection and rule-based detection models?

  • A. Rule-based detection defines legitimate data of users over a period of time and statistical detection defines it on an IF/THEN basis
  • B. Rule-based detection involves the collection of data in relation to the behavior of legitimate users over a period of time
  • C. Statistical detection involves the evaluation of an object on its intended actions before it executes that behavior
  • D. Statistical detection defines legitimate data of users over a period of time and rule-based detection defines it on an IF/THEN basis

Answer: D

 

NEW QUESTION 56
While viewing packet capture data, an analyst sees that one IP is sending and receiving traffic for multiple devices by modifying the IP header.
Which technology makes this behavior possible?

  • A. tunneling
  • B. encapsulation
  • C. TOR
  • D. NAT

Answer: D

Explanation:
Section: Network Intrusion Analysis

 

NEW QUESTION 57
What is a benefit of agent-based protection when compared to agentless protection?

  • A. It lowers maintenance costs
  • B. It manages numerous devices simultaneously
  • C. It collects and detects all traffic locally
  • D. It provides a centralized platform

Answer: D

Explanation:
Section: Security Concepts

 

NEW QUESTION 58
Which technology should be used to implement a solution that makes routing decisions based on HTTP header, uniform resource identifier, and SSL session ID attributes?

  • A. Proxy server
  • B. AWS
  • C. Load balancer
  • D. IIS

Answer: D

 

NEW QUESTION 59
Refer to the exhibit.

What is the expected result when the "Allow subdissector to reassemble TCP streams" feature is enabled?

  • A. unfragment TCP
  • B. extract a file from a packet capture
  • C. insert TCP subdissectors
  • D. disable TCP streams

Answer: A

 

NEW QUESTION 60
What is the difference between a threat and a risk?

  • A. Threat represents a potential danger that could take advantage of a weakness in a system
  • B. Threat represents a state of being exposed to an attack or a compromise either physically or logically
  • C. Risk represents the nonintentional interaction with uncertainty in the system
  • D. Risk represents the known and identified loss or danger in the system

Answer: A

 

NEW QUESTION 61
Which incidence response step includes identifying all hosts affected by an attack?

  • A. preparation
  • B. detection and analysis
  • C. post-incident activity
  • D. containment, eradication, and recovery

Answer: D

Explanation:
Section: Security Policies and Procedures

 

NEW QUESTION 62
Drag and drop the technology on the left onto the data type the technology provides on the right.

Answer:

Explanation:

 

NEW QUESTION 63
A security expert is working on a copy of the evidence, an ISO file that is saved in CDFS format. Which type of evidence is this file?

  • A. CD data copy prepared in Linux system
  • B. CD data copy prepared in Android-based system
  • C. CD data copy prepared in Windows
  • D. CD data copy prepared in Mac-based system

Answer: A

 

NEW QUESTION 64
Refer to the exhibit.

In which Linux log file is this output found?

  • A. /var/log/dmesg
  • B. var/log/var.log
  • C. /var/log/auth.log
  • D. /var/log/authorization.log

Answer: C

 

NEW QUESTION 65
What are two differences in how tampered and untampered disk images affect a security incident? (Choose two.)

  • A. The image is tampered if the stored hash and the computed hash match
  • B. The image is untampered if the stored hash and the computed hash match
  • C. Tampered images are used in the security investigation process
  • D. Tampered images are used in the incident recovery process
  • E. Untampered images are used in the security investigation process

Answer: B,E

Explanation:
Explanation
Cert Guide by Omar Santos, Chapter 9 - Introduction to digital Forensics. "When you collect evidence, you must protect its integrity. This involves making sure that nothing is added to the evidence and that nothing is deleted or destroyed (this is known as evidence preservation)."

 

NEW QUESTION 66
A SOC analyst is investigating an incident that involves a Linux system that is identifying specific sessions.
Which identifier tracks an active program?

  • A. process identification number
  • B. application identification number
  • C. runtime identification number
  • D. active process identification number

Answer: A

 

NEW QUESTION 67
A company is using several network applications that require high availability and responsiveness, such that milliseconds of latency on network traffic is not acceptable. An engineer needs to analyze the network and identify ways to improve traffic movement to minimize delays. Which information must the engineer obtain for this analysis?

  • A. output of routing protocol authentication failures and ports used
  • B. running processes on the applications and their total network usage
  • C. total throughput on the interface of the router and NetFlow records
  • D. deep packet captures of each application flow and duration

Answer: B

 

NEW QUESTION 68
Which technology on a host is used to isolate a running application from other applications?

  • A. application allow list
  • B. sandbox
  • C. application block list
  • D. host-based firewall

Answer: B

 

NEW QUESTION 69
Which piece of information is needed for attribution in an investigation?

  • A. 802.1x RADIUS authentication pass arid fail logs
  • B. proxy logs showing the source RFC 1918 IP addresses
  • C. RDP allowed from the Internet
  • D. known threat actor behavior

Answer: D

 

NEW QUESTION 70
......


Cisco 200-201 Exam Topics:

SectionWeightObjectives
Network Intrusion Analysis20%1.Map the provided events to source technologies
  • IDS/IPS
  • Firewall
  • Network application control
  • Proxy logs
  • Antivirus
  • Transaction data (NetFlow)

2.Compare impact and no impact for these items

  • False positive
  • False negative
  • True positive
  • True negative
  • Benign

3.Compare deep packet inspection with packet filtering and stateful firewall operation
4.Compare inline traffic interrogation and taps or traffic monitoring
5.Compare the characteristics of data obtained from taps or traffic monitoring and transactional data (NetFlow) in the analysis of network traffic
6.Extract files from a TCP stream when given a PCAP file and Wireshark
7.Identify key elements in an intrusion from a given PCAP file

  • Source address
  • Destination address
  • Source port
  • Destination port
  • Protocols
  • Payloads

8.Interpret the fields in protocol headers as related to intrusion analysis

  • Ethernet frame
  • IPv4
  • IPv6
  • TCP
  • UDP
  • ICMP
  • DNS
  • SMTP/POP3/IMAP
  • HTTP/HTTPS/HTTP2
  • ARP

9.Interpret common artifact elements from an event to identify an alert

  • IP address (source / destination)
  • Client and server port identity
  • Process (file or registry)
  • System (API calls)
  • Hashes
  • URI / URL

10.Interpret basic regular expressions

Security Concepts20%1. Describe the CIA triad
2. Compare security deployments
  • Network, endpoint, and application security systems
  • Agentless and agent-based protections
  • Legacy antivirus and antimalware
  • SIEM, SOAR, and log management

3. Describe security terms

  • Threat intelligence (TI)
  • Threat hunting
  • Malware analysis
  • Threat actor
  • Run book automation (RBA)
  • Reverse engineering
  • Sliding window anomaly detection
  • Principle of least privilege
  • Zero trust
  • Threat intelligence platform (TIP)

4. Compare security concepts

  • Risk (risk scoring/risk weighting, risk reduction, risk assessment)
  • Threat
  • Vulnerability
  • Exploit

5.Describe the principles of the defense-in-depth strategy
6.Compare access control models

  • Discretionary access control
  • Mandatory access control
  • Nondiscretionary access control
  • Authentication, authorization, accounting
  • Rule-based access control
  • Time-based access control
  • Role-based access control

7.Describe terms as defined in CVSS

  • Attack vector
  • Attack complexity
  • Privileges required
  • User interaction
  • Scope

8.Identify the challenges of data visibility (network, host, and cloud) in detection
9.Identify potential data loss from provided traffic profiles
10.Interpret the 5-tuple approach to isolate a compromised host in a grouped set of logs
11.Compare rule-based detection vs. behavioral and statistical detection

Security Monitoring25%1.Compare attack surface and vulnerability
2.Identify the types of data provided by these technologies
  • TCP dump
  • NetFlow
  • Next-gen firewall
  • Traditional stateful firewall
  • Application visibility and control
  • Web content filtering
  • Email content filtering

3.Describe the impact of these technologies on data visibility

  • Access control list
  • NAT/PAT
  • Tunneling
  • TOR
  • Encryption
  • P2P
  • Encapsulation
  • Load balancing

4.Describe the uses of these data types in security monitoring

  • Full packet capture
  • Session data
  • Transaction data
  • Statistical data
  • Metadata
  • Alert data

5.Describe network attacks, such as protocol-based, denial of service, distributed denial of service, and man-in-the-middle
6.Describe web application attacks, such as SQL injection, command injections, and cross-site scripting
7.Describe social engineering attacks
8.Describe endpoint-based attacks, such as buffer overflows, command and control (C2), malware, and ransomware
9.Describe evasion and obfuscation techniques, such as tunneling, encryption, and proxies
10.Describe the impact of certificates on security (includes PKI, public/private crossing the network, asymmetric/symmetric)
11.Identify the certificate components in a given scenario

  • Cipher-suite
  • X.509 certificates
  • Key exchange
  • Protocol version
  • PKCS

 

Cisco 200-201 Dumps PDF Are going to be The Best Score: https://www.examdumpsvce.com/200-201-valid-exam-dumps.html

200-201.pdf - Questions Answers PDF Sample Questions Reliable: https://drive.google.com/open?id=12ZEiYnWrol8j0r1zoL8tjGjNQFfXKqqw