[Dec 11, 2021] Latest 200-201 PDF Dumps & Real Tests Free Updated Today
200-201 Dumps With 100% Verified Q&As - Pass Guarantee or Full Refund
Security Procedures & Policies
This is the last topic that consists of 15% of the exam questions. To answer them, the interested individuals need to know how to perform the following tasks:
- Describing the elements in an event response plan as declared in NIST.SP800-61;
- Mapping the elements for preparation, analysis & detection, eradication, containment, and recovery, as well as post-incident analysis;
- Describing the concepts of evidence collection order, data integrity and preservation, and volatile data collection;
- Identifying listening ports, apps, running processes & tasks, and logged in service accounts applied for the server profiling.
- Describing the management concepts, including mobile device management, patch management, as well as asset, configuration, and vulnerability management;
- Applying the event-handling method to an incident;
- Identifying the session duration, total throughput, and ports used for the network profiling;
Cisco CyberOps Job Roles
We don’t miss a case of massive security breaches every year, which only goes to show why cybersecurity specialists are in high demand these days. In essence, cybersecurity is a sophisticated niche, with many organizations now willing to work with a team of security specialists as part of Security Operations Centers (SOC), which brings us to the question, which roles can you qualify for after passing 200-201 test? Well, with security still a vital component of many networking roles, it’s easy to see a lot of overlapping roles between these two paths. The four most popular roles that you can qualify for after completing this training include the following:
- Network Security Engineer;
- Cybersecurity Engineer;
- Security Engineer.
- Information Security Analyst;
NEW QUESTION 70
Which action should be taken if the system is overwhelmed with alerts when false positives and false negatives are compared?
- A. Redefine signature rules.
- B. Adjust the alerts schedule.
- C. Modify the settings of the intrusion detection system.
- D. Design criteria for reviewing alerts.
Answer: C
NEW QUESTION 71
Drag and drop the access control models from the left onto the correct descriptions on the right.
Answer:
Explanation:

NEW QUESTION 72
A user received an email attachment named "Hr405-report2609-empl094.exe" but did not run it. Which category of the cyber kill chain should be assigned to this type of event?
- A. delivery
- B. reconnaissance
- C. weaponization
- D. installation
Answer: D
NEW QUESTION 73
Which step in the incident response process researches an attacking host through logs in a SIEM?
- A. containment
- B. preparation
- C. eradication
- D. detection and analysis
Answer: D
NEW QUESTION 74
Which utility blocks a host portscan?
- A. antimalware
- B. sandboxing
- C. HIDS
- D. host-based firewall
Answer: D
NEW QUESTION 75 
An analyst is investigating a host in the network that appears to be communicating to a command and control server on the Internet. After collecting this packet capture the analyst cannot determine the technique and payload used for the communication.
Which obfuscation technique is the attacker using?
- A. Base64 encoding
- B. ROT13 encryption
- C. transport layer security encryption
- D. SHA-256 hashing
Answer: C
NEW QUESTION 76
Which regular expression is needed to capture the IP address 192.168.20.232?
- A. ^ (?:[0-9]f1,3}\.){1,4}
- B. ^ (?:[0-9]{1,3}\.){3}[0-9]{1,3}
- C. ^ (?:[0-9]{1,3}\.)'
- D. ^ ([0-9]-{3})
Answer: B
NEW QUESTION 77
What is the difference between mandatory access control (MAC) and discretionary access control (DAC)?
- A. MAC is controlled by the discretion of the owner and DAC is controlled by an administrator
- B. DAC is controlled by the operating system and MAC is controlled by an administrator
- C. MAC is the strictest of all levels of control and DAC is object-based access
- D. DAC is the strictest of all levels of control and MAC is object-based access
Answer: C
NEW QUESTION 78
What is a difference between SOAR and SIEM?
- A. SOAR platforms are used for threat and vulnerability management, but SIEM applications are not
- B. SIEM receives information from a single platform and delivers it to a SOAR
- C. SOAR receives information from a single platform and delivers it to a SIEM
- D. SIEM applications are used for threat and vulnerability management, but SOAR platforms are not
Answer: A
NEW QUESTION 79
Drag and drop the definition from the left onto the phase on the right to classify intrusion events according to the Cyber Kill Chain model.
Answer:
Explanation:

NEW QUESTION 80
The target web application server is running as the root user and is vulnerable to command injection. Which result of a successful attack is true?
- A. buffer overflow
- B. privilege escalation
- C. cross-site scripting request forgery
- D. cross-site scripting
Answer: C
NEW QUESTION 81
Refer to the exhibit.
What does the output indicate about the server with the IP address 172.18.104.139?
- A. running processes of the server
- B. open port of an FTP server
- C. open ports of an email server
- D. open ports of a web server
Answer: C
NEW QUESTION 82
Refer to the exhibit.
What information is depicted?
- A. IPS event data
- B. IIS data
- C. network discovery event
- D. NetFlow data
Answer: D
NEW QUESTION 83
Which two elements of the incident response process are stated in NIST Special Publication 800-61 r2? (Choose two.)
- A. vulnerability scoring
- B. vulnerability management
- C. risk assessment
- D. post-incident activity
- E. detection and analysis
Answer: D,E
NEW QUESTION 84
Refer to the exhibit.
What should be interpreted from this packet capture?
- A. IP address 179.179.69/50272/192.168.122.100/80/6 is sending a packet from port 80 of IP address
192.168.122.100 that is going to port 50272 of IP address 81.179.179.69 using IP protocol 6. - B. IP address 192.168.122.100/50272/81.179.179.69/80/6 is sending a packet from port 50272 of IP address
192.168.122.100 that is going to port 80 of IP address 81.179.179.69 using IP protocol 6. - C. IP address 192.168.122.100/50272/81.179.179.69/80/6 is sending a packet from port 80 of IP address
192.168.122.100 that is going to port 50272 of IP address 81.179.179.69 using IP protocol 6.7E503B693763E0113BE0CD2E4A16C9C4 - D. IP address 179.179.69/50272/192.168.122.100/80/6 is sending a packet from port 50272 of IP address
192.168.122.100 that is going to port 80 of IP address 81.179.179.69 using IP protocol 6.
Answer: B
NEW QUESTION 85
A user received a malicious attachment but did not run it.
Which category classifies the intrusion?
- A. reconnaissance
- B. installation
- C. weaponization
- D. delivery
Answer: D
NEW QUESTION 86
Which piece of information is needed for attribution in an investigation?
- A. RDP allowed from the Internet
- B. 802.1x RADIUS authentication pass arid fail logs
- C. proxy logs showing the source RFC 1918 IP addresses
- D. known threat actor behavior
Answer: D
NEW QUESTION 87
Which two elements are used for profiling a network? (Choose two.)
- A. OS fingerprint
- B. running processes
- C. session duration
- D. listening ports
- E. total throughout
Answer: A,D
NEW QUESTION 88
Refer to the exhibit.
What is occurring in this network?
- A. DNS cache poisoning
- B. ARP cache poisoning
- C. MAC flooding attack
- D. MAC address table overflow
Answer: B
NEW QUESTION 89
......
2021 Valid 200-201 test answers & Cisco Exam PDF: https://www.examsreviews.com/200-201-pass4sure-exam-review.html
Pass Cisco 200-201 Exam With Practice Test Questions Dumps Bundle: https://drive.google.com/open?id=1527FinzTx-qpeFTkzqVAUuqR5RTFQ1S1