Pass CyberOps Associate 200-201 exam [Jan 28, 2023] Updated 260 Questions [Q127-Q142]

Share

Pass CyberOps Associate 200-201 exam [Jan 28, 2023] Updated 260 Questions

Cisco 200-201 Actual Questions and 100% Cover Real Exam Questions


Exam Topics

The Cisco 200-201 exam will validate your skills and knowledge of security monitoring, security concepts, security policies & procedures, host-based analysis, and network intrusion analysis. All in all, its content comes with 5 topics that are listed as follows:

Security Concepts

This domain makes up 20% of the exam content and measures the applicants’ abilities to perform the following tasks:

  • Understand CVSS – You need to have knowledge of the attack vector, privileges required, scope, and user interaction;
  • Compare various security concepts – As for this one, it covers the details of risk scoring, assessment, and reduction as well as vulnerability, exploit, and threat;
  • Determine the possible data loss from the available traffic profiles;
  • Analyze security deployments – It includes the agent-based and agentless protections as well as network, endpoint, and application security systems. You should also know about log management, SOAR & SIEM, and Legacy antivirus & antimalware;
  • Explain the policies of the defense-in-depth approach;
  • Define security terms – The potential candidates have to know about hunting, actor & threat intelligence, and TI platform, malware analysis, run book cybernation, as well as sliding window exception detection;
  • Classify the difficulties of data visibility in detention;
  • Describe the 5-tuple method to separate a compromised host in a grouped set of logs.

 

NEW QUESTION 127
Refer to the exhibit.

Which type of log is displayed?

  • A. proxy
  • B. IDS
  • C. sys
  • D. NetFlow

Answer: C

 

NEW QUESTION 128
Drag and drop the event term from the left onto the description on the right.

Answer:

Explanation:

 

NEW QUESTION 129
Drag and drop the definition from the left onto the phase on the right to classify intrusion events according to the Cyber Kill Chain model.

Answer:

Explanation:

 

NEW QUESTION 130
Refer to the exhibit.

Which type of log is displayed?

  • A. proxy
  • B. IDS
  • C. NetFlow
  • D. sys

Answer: C

 

NEW QUESTION 131
What are the two characteristics of the full packet captures? (Choose two.)

  • A. Identifying network loops and collision domains.
  • B. Providing a historical record of a network transaction.
  • C. Troubleshooting the cause of security and performance issues.
  • D. Reassembling fragmented traffic from raw data.
  • E. Detecting common hardware faults and identify faulty assets.

Answer: B,D

Explanation:
Section: Security Monitoring

 

NEW QUESTION 132
Refer to the exhibit.

An analyst received this alert from the Cisco ASA device, and numerous activity logs were produced. How should this type of evidence be categorized?

  • A. best
  • B. corroborative
  • C. circumstantial
  • D. indirect

Answer: B

Explanation:
Explanation
Indirect=circumstantail so there is no posibility to match A or B (only one answer is needed in this question).
For suer it's not a BEST evidence - this FW data inform only of DROPPED traffic. If smth happend inside network, presented evidence could be used to support other evidences or make our narreation stronger but alone it's mean nothing.

 

NEW QUESTION 133
Which system monitors local system operation and local network access for violations of a security policy?

  • A. host-based intrusion detection
  • B. host-based firewall
  • C. systems-based sandboxing
  • D. antivirus

Answer: B

 

NEW QUESTION 134

Refer to the exhibit. An employee received an email from an unknown sender with an attachment and reported it as a phishing attempt. An engineer uploaded the file to Cuckoo for further analysis. What should an engineer interpret from the provided Cuckoo report?

  • A. The file is clean and does not represent a risk.
  • B. MD5 of the file was not identified as malicious.
  • C. Cuckoo cleaned the malicious file and prepared it for usage.
  • D. Win32.polip.a.exe is an executable file and should be flagged as malicious.

Answer: C

 

NEW QUESTION 135
What is a benefit of agent-based protection when compared to agentless protection?

  • A. It manages numerous devices simultaneously
  • B. It provides a centralized platform
  • C. It collects and detects all traffic locally
  • D. It lowers maintenance costs

Answer: B

Explanation:
Section: Security Concepts

 

NEW QUESTION 136
Which two elements of the incident response process are stated in NIST SP 800-61 r2? (Choose two.)

  • A. detection and analysis
  • B. risk assessment
  • C. vulnerability management
  • D. post-incident activity
  • E. vulnerability scoring

Answer: A,D

 

NEW QUESTION 137
Which evasion technique is indicated when an intrusion detection system begins receiving an abnormally high volume of scanning from numerous sources?

  • A. tunneling
  • B. resource exhaustion
  • C. traffic fragmentation
  • D. timing attack

Answer: B

 

NEW QUESTION 138
An organization has recently adjusted its security stance in response to online threats made by a known hacktivist group.
What is the initial event called in the NIST SP800-61?

  • A. instigator
  • B. trigger
  • C. precursor
  • D. online assault

Answer: C

Explanation:
Explanation
A precursor is a sign that a cyber-attack is about to occur on a system or network. An indicator is the actual alerts that are generated as an attack is happening. Therefore, as a security professional, it's important to know where you can find both precursor and indicator sources of information.
The following are common sources of precursor and indicator information:
* Security Information and Event Management (SIEM)
* Anti-virus and anti-spam software
* File integrity checking applications/software
* Logs from various sources (operating systems, devices, and applications)
* People who report a security incident
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

 

NEW QUESTION 139
An engineer received a flood of phishing emails from HR with the source address HRjacobm@companycom.
What is the threat actor in this scenario?

  • A. HR
  • B. receiver
  • C. sender
  • D. phishing email

Answer: C

 

NEW QUESTION 140
An engineer is addressing a connectivity issue between two servers where the remote server is unable to establish a successful session. Initial checks show that the remote server is not receiving an SYN-ACK while establishing a session by sending the first SYN. What is causing this issue?

  • A. incorrect snaplen configuration
  • B. incorrect OSI configuration
  • C. incorrect TCP handshake
  • D. incorrect UDP handshake

Answer: C

 

NEW QUESTION 141
Which principle is being followed when an analyst gathers information relevant to a security incident to determine the appropriate course of action?

  • A. rapid response
  • B. data mining
  • C. due diligence
  • D. decision making

Answer: A

 

NEW QUESTION 142
......


Understanding functional and technical aspects of Cisco Cybersecurity Operations Fundamentals v1.0 (200-201 CBROPS) Security Concepts

The following will be discussed in CISCO 200-201 exam dumps:

  • Role-based access control
  • Network, endpoint, and application security systems
  • Threat hunting
  • Compare security concepts
  • Malware analysis
  • Sliding window anomaly detection
  • Rule-based access control
  • SIEM, SOAR, and log management
  • Identify the challenges of data visibility (network, host, and cloud) in detection
  • Compare access control models
  • Run book automation (RBA)
  • Interpret the 5-tuple approach to isolate a compromised host in a grouped set of logs
  • Scope
  • Nondiscretionary access control
  • Reverse engineering
  • Attack vector
  • Principle of least privilege
  • Exploit
  • Threat intelligence (TI)
  • Legacy antivirus and antimalware
  • Discretionary access control
  • Agentless and agent-based protections
  • Authentication, authorization, accounting
  • User interaction
  • Vulnerability
  • Risk (risk scoring/risk weighting, risk reduction, risk assessment)

 

Cisco 200-201 Real 2023 Braindumps Mock Exam Dumps: https://www.testsdumps.com/200-201_real-exam-dumps.html

200-201 Free Exam Questions and Answers PDF Updated on Jan-2023: https://drive.google.com/open?id=1FDr1OKXIMEkgq2J5gFr1YYOwdagCsNDY