[Jul-2021] Pass Cisco 200-201 Exam in First Attempt Guaranteed!
Full 200-201 Practice Test and 182 unique questions with explanations waiting just for you, get it now!
NEW QUESTION 65
Refer to the exhibit.
What is shown in this PCAP file?
- A. The HTTP GET is encoded.
- B. The protocol is TCP.
- C. Timestamps are indicated with error.
- D. The User-Agent is Mozilla/5.0.
Answer: C
NEW QUESTION 66
Which two pieces of information are collected from the IPv4 protocol header? (Choose two.)
- A. UDP port from which the traffic is sourced
- B. UDP port to which the traffic is destined
- C. TCP port from which the traffic was sourced
- D. destination IP address of the packet
- E. source IP address of the packet
Answer: D,E
Explanation:
Section: Network Intrusion Analysis
NEW QUESTION 67
W[^t is vulnerability management?
- A. A security practice focused on clarifying and narrowing intrusion points.
- B. A security practice of performing actions rather than acknowledging the threats.
- C. A process to identify and remediate existing weaknesses.
- D. A process to recover from service interruptions and restore business-critical applications
Answer: C
NEW QUESTION 68
How is NetFlow different than traffic mirroring?
- A. NetFlow generates more data than traffic mirroring
- B. Traffic mirroring costs less to operate than NetFlow
- C. NetFlow collects metadata and traffic mirroring clones data
- D. Traffic mirroring impacts switch performance and NetFlow does not
Answer: C
Explanation:
Section: Security Monitoring
NEW QUESTION 69
Which utility blocks a host portscan?
- A. host-based firewall
- B. HIDS
- C. sandboxing
- D. antimalware
Answer: A
NEW QUESTION 70
A security engineer has a video of a suspect entering a data center that was captured on the same day that files in the same data center were transferred to a competitor.
Which type of evidence is this?
- A. physical evidence
- B. best evidence
- C. indirect evidence
- D. prima facie evidence
Answer: C
NEW QUESTION 71
Refer to the exhibit.
What should be interpreted from this packet capture?
- A. 192.168.122.100 is sending a packet from port 80 to port 50272 of IP address 81.179.179.69 using UDP protocol.
- B. 81.179.179.69 is sending a packet from port 50272 to port 80 of IP address 192.168.122.100 using TCP UDP protocol.
- C. 192.168.122.100 is sending a packet from port 50272 to port 80 of IP address 81.179.179.69 using TCP protocol.
- D. 81.179.179.69 is sending a packet from port 80 to port 50272 of IP address 192.168.122.100 using UDP protocol.
Answer: C
NEW QUESTION 72
Drag and drop the elements from the left into the correct order for incident handling on the right.
Answer:
Explanation:
NEW QUESTION 73
Refer to the exhibit.
What is the expected result when the "Allow subdissector to reassemble TCP streams" feature is enabled?
- A. disable TCP streams
- B. unfragment TCP
- C. insert TCP subdissectors
- D. extract a file from a packet capture
Answer: B
NEW QUESTION 74
A security engineer deploys an enterprise-wide host/endpoint technology for all of the company's corporate PCs. Management requests the engineer to block a selected set of applications on all PCs.
Which technology should be used to accomplish this task?
- A. host-based IDS
- B. application whitelisting/blacklisting
- C. antivirus/antispyware software
- D. network NGFW
Answer: B
NEW QUESTION 75 
Refer to the exhibit. Which event is occurring?
- A. A URL is being evaluated to see if it has a malicious binary
- B. A binary on VM cuckoo1 is being submitted for evaluation
- C. A binary is being submitted to run on VM cuckoo1
- D. A binary named "submit" is running on VM cuckoo1.
Answer: B
NEW QUESTION 76
What is the difference between the ACK flag and the RST flag in the NetFlow log session?
- A. The ACK flag confirms the receipt of the prior segment, and the RST flag allows for the spontaneous termination of a connection
- B. The RST flag confirms the beginning of the TCP connection, and the ACK flag responds when the data for the payload is complete
- C. The ACK flag confirms the beginning of the TCP connection, and the RST flag responds when the data for the payload is complete
- D. The RST flag confirms the receipt of the prior segment, and the ACK flag allows for the spontaneous termination of a connection
Answer: A
NEW QUESTION 77
Refer to the exhibit.
What is the potential threat identified in this Stealthwatch dashboard?
- A. A policy violation is active for host 10.201.3.149.
- B. A host on the network is sending a DDoS attack to another inside host.
- C. A policy violation is active for host 10.10.101.24.
- D. There are two active data exfiltration alerts.
Answer: D
NEW QUESTION 78
Which two elements of the incident response process are stated in NIST Special Publication 800-61 r2?
(Choose two.)
- A. vulnerability management
- B. detection and analysis
- C. vulnerability scoring
- D. risk assessment
- E. post-incident activity
Answer: B,E
NEW QUESTION 79
Which HTTP header field is used in forensics to identify the type of browser used?
- A. user-agent
- B. host
- C. accept-language
- D. referrer
Answer: A
Explanation:
Section: Network Intrusion Analysis
Explanation/Reference:
NEW QUESTION 80
Refer to the exhibit.
What should be interpreted from this packet capture?
- A. IP address 192.168.122.100/50272/81.179.179.69/80/6 is sending a packet from port 50272 of IP address
192.168.122.100 that is going to port 80 of IP address 81.179.179.69 using IP protocol 6. - B. IP address 179.179.69/50272/192.168.122.100/80/6 is sending a packet from port 50272 of IP address
192.168.122.100 that is going to port 80 of IP address 81.179.179.69 using IP protocol 6. - C. IP address 179.179.69/50272/192.168.122.100/80/6 is sending a packet from port 80 of IP address
192.168.122.100 that is going to port 50272 of IP address 81.179.179.69 using IP protocol 6. - D. IP address 192.168.122.100/50272/81.179.179.69/80/6 is sending a packet from port 80 of IP address
192.168.122.100 that is going to port 50272 of IP address 81.179.179.69 using IP protocol 6.7E503B693763E0113BE0CD2E4A16C9C4
Answer: A
NEW QUESTION 81
Which open-sourced packet capture tool uses Linux and Mac OS X operating systems?
- A. netsh
- B. tcpdump
- C. NetScout
- D. SolarWinds
Answer: B
NEW QUESTION 82
Which security technology allows only a set of pre-approved applications to run on a system?
- A. application-level whitelisting
- B. antivirus
- C. application-level blacklisting
- D. host-based IPS
Answer: A
NEW QUESTION 83
......
Prepare for your Cisco certification with the updated BraindumpsVCE 200-201 exam questions: https://drive.google.com/open?id=1n3enOXLQ4R9FXTBktqpWcHc_xLh7wwGh
Get Latest 200-201 Dumps Exam Questions in here: https://www.braindumpsvce.com/200-201_exam-dumps-torrent.html