[Jul-2021] Pass Cisco 200-201 Exam in First Attempt Guaranteed! Full 200-201 Practice Test and 182 unique questions with explanations waiting just for you, get it now! NEW QUESTION 65 Refer to the exhibit.What is shown in this PCAP file? A. The HTTP GET is encoded. B. The protocol is TCP. C. Timestamps are indicated with error. D. The User-Agent is Mozilla/5.0. Answer: C NEW QUESTION 66 Which two pieces [...]

Cisco 200-201 Dumps Updated [Jul-2021] Get 100% Real Exam Questions! [Q65-Q83]

Share

[Jul-2021] Pass Cisco 200-201 Exam in First Attempt Guaranteed!

Full 200-201 Practice Test and 182 unique questions with explanations waiting just for you, get it now!

NEW QUESTION 65
Refer to the exhibit.

What is shown in this PCAP file?

  • A. The HTTP GET is encoded.
  • B. The protocol is TCP.
  • C. Timestamps are indicated with error.
  • D. The User-Agent is Mozilla/5.0.

Answer: C

 

NEW QUESTION 66
Which two pieces of information are collected from the IPv4 protocol header? (Choose two.)

  • A. UDP port from which the traffic is sourced
  • B. UDP port to which the traffic is destined
  • C. TCP port from which the traffic was sourced
  • D. destination IP address of the packet
  • E. source IP address of the packet

Answer: D,E

Explanation:
Section: Network Intrusion Analysis

 

NEW QUESTION 67
W[^t is vulnerability management?

  • A. A security practice focused on clarifying and narrowing intrusion points.
  • B. A security practice of performing actions rather than acknowledging the threats.
  • C. A process to identify and remediate existing weaknesses.
  • D. A process to recover from service interruptions and restore business-critical applications

Answer: C

 

NEW QUESTION 68
How is NetFlow different than traffic mirroring?

  • A. NetFlow generates more data than traffic mirroring
  • B. Traffic mirroring costs less to operate than NetFlow
  • C. NetFlow collects metadata and traffic mirroring clones data
  • D. Traffic mirroring impacts switch performance and NetFlow does not

Answer: C

Explanation:
Section: Security Monitoring

 

NEW QUESTION 69
Which utility blocks a host portscan?

  • A. host-based firewall
  • B. HIDS
  • C. sandboxing
  • D. antimalware

Answer: A

 

NEW QUESTION 70
A security engineer has a video of a suspect entering a data center that was captured on the same day that files in the same data center were transferred to a competitor.
Which type of evidence is this?

  • A. physical evidence
  • B. best evidence
  • C. indirect evidence
  • D. prima facie evidence

Answer: C

 

NEW QUESTION 71
Refer to the exhibit.

What should be interpreted from this packet capture?

  • A. 192.168.122.100 is sending a packet from port 80 to port 50272 of IP address 81.179.179.69 using UDP protocol.
  • B. 81.179.179.69 is sending a packet from port 50272 to port 80 of IP address 192.168.122.100 using TCP UDP protocol.
  • C. 192.168.122.100 is sending a packet from port 50272 to port 80 of IP address 81.179.179.69 using TCP protocol.
  • D. 81.179.179.69 is sending a packet from port 80 to port 50272 of IP address 192.168.122.100 using UDP protocol.

Answer: C

 

NEW QUESTION 72
Drag and drop the elements from the left into the correct order for incident handling on the right.

Answer:

Explanation:

 

NEW QUESTION 73
Refer to the exhibit.

What is the expected result when the "Allow subdissector to reassemble TCP streams" feature is enabled?

  • A. disable TCP streams
  • B. unfragment TCP
  • C. insert TCP subdissectors
  • D. extract a file from a packet capture

Answer: B

 

NEW QUESTION 74
A security engineer deploys an enterprise-wide host/endpoint technology for all of the company's corporate PCs. Management requests the engineer to block a selected set of applications on all PCs.
Which technology should be used to accomplish this task?

  • A. host-based IDS
  • B. application whitelisting/blacklisting
  • C. antivirus/antispyware software
  • D. network NGFW

Answer: B

 

NEW QUESTION 75

Refer to the exhibit. Which event is occurring?

  • A. A URL is being evaluated to see if it has a malicious binary
  • B. A binary on VM cuckoo1 is being submitted for evaluation
  • C. A binary is being submitted to run on VM cuckoo1
  • D. A binary named "submit" is running on VM cuckoo1.

Answer: B

 

NEW QUESTION 76
What is the difference between the ACK flag and the RST flag in the NetFlow log session?

  • A. The ACK flag confirms the receipt of the prior segment, and the RST flag allows for the spontaneous termination of a connection
  • B. The RST flag confirms the beginning of the TCP connection, and the ACK flag responds when the data for the payload is complete
  • C. The ACK flag confirms the beginning of the TCP connection, and the RST flag responds when the data for the payload is complete
  • D. The RST flag confirms the receipt of the prior segment, and the ACK flag allows for the spontaneous termination of a connection

Answer: A

 

NEW QUESTION 77
Refer to the exhibit.

What is the potential threat identified in this Stealthwatch dashboard?

  • A. A policy violation is active for host 10.201.3.149.
  • B. A host on the network is sending a DDoS attack to another inside host.
  • C. A policy violation is active for host 10.10.101.24.
  • D. There are two active data exfiltration alerts.

Answer: D

 

NEW QUESTION 78
Which two elements of the incident response process are stated in NIST Special Publication 800-61 r2?
(Choose two.)

  • A. vulnerability management
  • B. detection and analysis
  • C. vulnerability scoring
  • D. risk assessment
  • E. post-incident activity

Answer: B,E

 

NEW QUESTION 79
Which HTTP header field is used in forensics to identify the type of browser used?

  • A. user-agent
  • B. host
  • C. accept-language
  • D. referrer

Answer: A

Explanation:
Section: Network Intrusion Analysis
Explanation/Reference:

 

NEW QUESTION 80
Refer to the exhibit.

What should be interpreted from this packet capture?

  • A. IP address 192.168.122.100/50272/81.179.179.69/80/6 is sending a packet from port 50272 of IP address
    192.168.122.100 that is going to port 80 of IP address 81.179.179.69 using IP protocol 6.
  • B. IP address 179.179.69/50272/192.168.122.100/80/6 is sending a packet from port 50272 of IP address
    192.168.122.100 that is going to port 80 of IP address 81.179.179.69 using IP protocol 6.
  • C. IP address 179.179.69/50272/192.168.122.100/80/6 is sending a packet from port 80 of IP address
    192.168.122.100 that is going to port 50272 of IP address 81.179.179.69 using IP protocol 6.
  • D. IP address 192.168.122.100/50272/81.179.179.69/80/6 is sending a packet from port 80 of IP address
    192.168.122.100 that is going to port 50272 of IP address 81.179.179.69 using IP protocol 6.7E503B693763E0113BE0CD2E4A16C9C4

Answer: A

 

NEW QUESTION 81
Which open-sourced packet capture tool uses Linux and Mac OS X operating systems?

  • A. netsh
  • B. tcpdump
  • C. NetScout
  • D. SolarWinds

Answer: B

 

NEW QUESTION 82
Which security technology allows only a set of pre-approved applications to run on a system?

  • A. application-level whitelisting
  • B. antivirus
  • C. application-level blacklisting
  • D. host-based IPS

Answer: A

 

NEW QUESTION 83
......

Prepare for your Cisco certification with the updated BraindumpsVCE 200-201 exam questions: https://drive.google.com/open?id=1n3enOXLQ4R9FXTBktqpWcHc_xLh7wwGh

Get Latest 200-201 Dumps Exam Questions in here: https://www.braindumpsvce.com/200-201_exam-dumps-torrent.html