Cisco 200-201 Dumps - The Sure Way To Pass Exam
200-201 Exam Questions (Updated 2021) 100% Real Question Answers
200-201 Details
The test has a duration of 120 minutes during which the candidates will have to answer 95 to 105 questions. Applicants can enroll in their exams by using the Pearson VUE platform after having created an account there and selected the “proctored exam” section. Thereafter, you should search the code 200-201 and follow the instructions to fully register. The fee for this test is $300 and it's available in the English language only.
NEW QUESTION 39
What are the two characteristics of the full packet captures? (Choose two.)
- A. Detecting common hardware faults and identify faulty assets.
- B. Troubleshooting the cause of security and performance issues.
- C. Identifying network loops and collision domains.
- D. Reassembling fragmented traffic from raw data.
- E. Providing a historical record of a network transaction.
Answer: D,E
Explanation:
Section: Security Monitoring
NEW QUESTION 40
Refer to the exhibit.
What should be interpreted from this packet capture?
- A. 81.179.179.69 is sending a packet from port 80 to port 50272 of IP address 192.168.122.100 using UDP protocol.
- B. 81.179.179.69 is sending a packet from port 50272 to port 80 of IP address 192.168.122.100 using TCP UDP protocol.
- C. 192.168.122.100 is sending a packet from port 80 to port 50272 of IP address 81.179.179.69 using UDP protocol.
- D. 192.168.122.100 is sending a packet from port 50272 to port 80 of IP address 81.179.179.69 using TCP protocol.
Answer: D
NEW QUESTION 41
How does an SSL certificate impact security between the client and the server?
- A. by enabling an authenticated channel between the client and the server
- B. by creating an encrypted channel between the client and the server
- C. by creating an integrated channel between the client and the server
- D. by enabling an authorized channel between the client and the server
Answer: B
NEW QUESTION 42
Which type of data consists of connection level, application-specific records generated from network traffic?
- A. transaction data
- B. statistical data
- C. alert data
- D. location data
Answer: A
Explanation:
Section: Security Monitoring
Explanation/Reference:
NEW QUESTION 43
Drag and drop the uses on the left onto the type of security system on the right.
Answer:
Explanation:
NEW QUESTION 44
Which regex matches only on all lowercase letters?
- A. [a−z]+
- B. a−z+
- C. [^a−z]+
- D. a*z+
Answer: A
Explanation:
Section: Network Intrusion Analysis
NEW QUESTION 45
Which attack is the network vulnerable to when a stream cipher like RC4 is used twice with the same key?
- A. meet-in-the-middle attack
- B. forgery attack
- C. ciphertext-only attack
- D. plaintext-only attack
Answer: C
Explanation:
Explanation/Reference:
NEW QUESTION 46
An engineer needs to have visibility on TCP bandwidth usage, response time, and latency, combined with deep packet inspection to identify unknown software by its network traffic flow. Which two features of Cisco Application Visibility and Control should the engineer use to accomplish this goal? (Choose two.)
- A. application recognition
- B. management and reporting
- C. traffic filtering
- D. adaptive AVC
- E. metrics collection and exporting
Answer: A,B
NEW QUESTION 47
What is the difference between deep packet inspection and stateful inspection?
- A. Deep packet inspection is more secure than stateful inspection on Layer 4
- B. Deep packet inspection allows visibility on Layer 7 and stateful inspection allows visibility on Layer 4
- C. Stateful inspection verifies contents at Layer 4 and deep packet inspection verifies connection at Layer 7
- D. Stateful inspection is more secure than deep packet inspection on Layer 7
Answer: B
NEW QUESTION 48
Drag and drop the access control models from the left onto the correct descriptions on the right.
Answer:
Explanation:

NEW QUESTION 49
What causes events on a Windows system to show Event Code 4625 in the log messages?
- A. The system detected an XSS attack
- B. Another device is gaining root access to the system
- C. Someone is trying a brute force attack on the network
- D. A privileged user successfully logged into the system
Answer: C
NEW QUESTION 50
A company is using several network applications that require high availability and responsiveness, such that milliseconds of latency on network traffic is not acceptable. An engineer needs to analyze the network and identify ways to improve traffic movement to minimize delays. Which information must the engineer obtain for this analysis?
- A. output of routing protocol authentication failures and ports used
- B. running processes on the applications and their total network usage
- C. deep packet captures of each application flow and duration
- D. total throughput on the interface of the router and NetFlow records
Answer: B
NEW QUESTION 51
A network engineer discovers that a foreign government hacked one of the defense contractors in their home country and stole intellectual property. What is the threat agent in this situation?
- A. the intellectual property that was stolen
- B. the foreign government that conducted the attack
- C. the method used to conduct the attack
- D. the defense contractor who stored the intellectual property
Answer: B
NEW QUESTION 52
Which data format is the most efficient to build a baseline of traffic seen over an extended period of time?
- A. syslog messages
- B. NetFlow
- C. full packet capture
- D. firewall event logs
Answer: B
NEW QUESTION 53
An organization's security team has detected network spikes coming from the internal network. An investigation has concluded that the spike in traffic was from intensive network scanning How should the analyst collect the traffic to isolate the suspicious host?
- A. based on the protocols used
- B. based on the most used applications
- C. by most used ports
- D. by most active source IP
Answer: A
NEW QUESTION 54
In a SOC environment, what is a vulnerability management metric?
- A. full assets scan
- B. code signing enforcement
- C. single factor authentication
- D. internet exposed devices
Answer: C
NEW QUESTION 55
Drag and drop the definition from the left onto the phase on the right to classify intrusion events according to the Cyber Kill Chain model.
Answer:
Explanation:

NEW QUESTION 56
How does an SSL certificate impact security between the client and the server?
- A. by enabling an authenticated channel between the client and the server
- B. by creating an encrypted channel between the client and the server
- C. by creating an integrated channel between the client and the server
- D. by enabling an authorized channel between the client and the server
Answer: B
Explanation:
Section: Security Monitoring
NEW QUESTION 57
Which evasion technique is a function of ransomware?
- A. resource exhaustion
- B. encryption
- C. extended sleep calls
- D. encoding
Answer: B
NEW QUESTION 58
Which security technology allows only a set of pre-approved applications to run on a system?
- A. host-based IPS
- B. antivirus
- C. application-level blacklisting
- D. application-level whitelisting
Answer: D
NEW QUESTION 59
What is the difference between an attack vector and attack surface?
- A. An attack vector identifies components that can be exploited; and an attack surface identifies the potential path an attack can take to penetrate the network.
- B. An attack surface identifies vulnerabilities that require user input or validation; and an attack vector identifies vulnerabilities that are independent of user actions.
- C. An attack surface recognizes which network parts are vulnerable to an attack; and an attack vector identifies which attacks are possible with these vulnerabilities.
- D. An attack vector identifies the potential outcomes of an attack; and an attack surface launches an attack using several methods against the identified vulnerabilities.
Answer: C
Explanation:
Section: Security Concepts
NEW QUESTION 60
Which list identifies the information that the client sends to the server in the negotiation phase of the TLS handshake?
- A. ClientHello, TLS versions it supports, cipher-suites it supports, and suggested compression methods
- B. ClientStart, TLS versions it supports, cipher-suites it supports, and suggested compression methods
- C. ClientStart, ClientKeyExchange, cipher-suites it supports, and suggested compression methods
- D. ClientHello, ClientKeyExchange, cipher-suites it supports, and suggested compression methods
Answer: A
NEW QUESTION 61 
Refer to the exhibit. In which Linux log file is this output found?
- A. /var/log/authorization.log
- B. /var/log/dmesg
- C. var/log/var.log
- D. /var/log/auth.log
Answer: D
Explanation:
Section: Host-Based Analysis
NEW QUESTION 62
Which attack method intercepts traffic on a switched network?
- A. denial of service
- B. command and control
- C. ARP cache poisoning
- D. DHCP snooping
Answer: C
Explanation:
Explanation
An ARP-based MITM attack is achieved when an attacker poisons the ARP cache of two devices with the MAC address of the attacker's network interface card (NIC). Once the ARP caches have been successfully poisoned, each victim device sends all its packets to the attacker when communicating to the other device and puts the attacker in the middle of the communications path between the two victim devices. It allows an attacker to easily monitor all communication between victim devices. The intent is to intercept and view the information being passed between the two victim devices and potentially introduce sessions and traffic between the two victim devices
NEW QUESTION 63
Which step in the incident response process researches an attacking host through logs in a SIEM?
- A. containment
- B. preparation
- C. eradication
- D. detection and analysis
Answer: D
NEW QUESTION 64
......
Pass Cisco 200-201 Exam Quickly With BraindumpsVCE: https://www.braindumpsvce.com/200-201_exam-dumps-torrent.html
Prepare 200-201 Question Answers - 200-201 Exam Dumps: https://drive.google.com/open?id=1Q5JlGHJRa-DJWc_izHh4OQPq_uV77nVW