Download 200-201 Exam Dumps Questions to get 100% Success in Cisco
100% Accurate Answers! 200-201 Actual Real Exam Questions
Certification Path
If you want to upgrade your CyberOps skills from associate to a professional level, you can continue your education by pursuing the Cisco Certified CyberOps Professional certificate, which will bring even more perks to your career.
NEW QUESTION 31
What should an engineer use to aid the trusted exchange of public keys between user tom0411976943 and dan1968754032?
- A. registration authority data
- B. central key management server
- C. web of trust
- D. trusted certificate authorities
Answer: D
NEW QUESTION 32
An engineer is analyzing a recent breach where confidential documents were altered and stolen by the receptionist Further analysis shows that the threat actor connected an externa USB device to bypass security restrictions and steal data The engineer could not find an external USB device Which piece of information must an engineer use for attribution in an investigation?
- A. stolen data and its criticality assessment
- B. receptionist and the actions performed
- C. external USB device
- D. list of security restrictions and privileges boundaries bypassed
Answer: B
NEW QUESTION 33 
Refer to the exhibit. Which two elements in the table are parts of the 5-tuple? (Choose two.)
- A. Initiator User
- B. Initiator IP
- C. Source Port
- D. First Packet
- E. Ingress Security Zone
Answer: B,C
Explanation:
Section: Security Concepts
NEW QUESTION 34
Drag and drop the security concept from the left onto the example of that concept on the right.
Answer:
Explanation:
Explanation
Table Description automatically generated
NEW QUESTION 35
Refer to the exhibit.
What is occurring?
- A. Regular GET requests
- B. Insecure Deserialization
- C. Cross-Site Scripting attack
- D. XML External Entitles attack
Answer: D
NEW QUESTION 36
A SOC analyst is investigating an incident that involves a Linux system that is identifying specific sessions. Which identifier tracks an active program?
- A. active process identification number
- B. runtime identification number
- C. process identification number
- D. application identification number
Answer: C
NEW QUESTION 37
Refer to the exhibit.
What should be interpreted from this packet capture?
- A. 192.168.122.100 is sending a packet from port 50272 to port 80 of IP address 81.179.179.69 using TCP protocol.
- B. 192.168.122.100 is sending a packet from port 80 to port 50272 of IP address 81.179.179.69 using UDP protocol.
- C. 81.179.179.69 is sending a packet from port 50272 to port 80 of IP address 192.168.122.100 using TCP UDP protocol.
- D. 81.179.179.69 is sending a packet from port 80 to port 50272 of IP address 192.168.122.100 using UDP protocol.
Answer: A
NEW QUESTION 38 
Refer to the exhibit. Which packet contains a file that is extractable within Wireshark?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: D
Explanation:
Explanation
NEW QUESTION 39
A malicious file has been identified in a sandbox analysis tool.
Which piece of information is needed to search for additional downloads of this file by other hosts?
- A. file header type
- B. file name
- C. file hash value
- D. file size
Answer: C
NEW QUESTION 40
A SOC analyst is investigating an incident that involves a Linux system that is identifying specific sessions.
Which identifier tracks an active program?
- A. active process identification number
- B. runtime identification number
- C. process identification number
- D. application identification number
Answer: C
NEW QUESTION 41
When trying to evade IDS/IPS devices, which mechanism allows the user to make the data incomprehensible without a specific key, certificate, or password?
- A. stenography
- B. pivoting
- C. fragmentation
- D. encryption
Answer: A
NEW QUESTION 42
An organization's security team has detected network spikes coming from the internal network. An investigation has concluded that the spike in traffic was from intensive network scanning How should the analyst collect the traffic to isolate the suspicious host?
- A. based on the most used applications
- B. by most used ports
- C. based on the protocols used
- D. by most active source IP
Answer: C
NEW QUESTION 43
An engineer runs a suspicious file in a sandbox analysis tool to see the outcome. The analysis report shows that outbound callouts were made post infection.
Which two pieces of information from the analysis report are needed to investigate the callouts? (Choose two.)
- A. dropped files
- B. signatures
- C. domain names
- D. host IP addresses
- E. file size
Answer: C,D
NEW QUESTION 44
What is the relationship between a vulnerability and a threat?
- A. A vulnerability is a calculation of the potential loss caused by a threat
- B. A threat exploits a vulnerability
- C. A vulnerability exploits a threat
- D. A threat is a calculation of the potential loss caused by a vulnerability
Answer: B
NEW QUESTION 45
A security engineer deploys an enterprise-wide host/endpoint technology for all of the company's corporate PCs. Management requests the engineer to block a selected set of applications on all PCs.
Which technology should be used to accomplish this task?
- A. application whitelisting/blacklisting
- B. antivirus/antispyware software
- C. network NGFW
- D. host-based IDS
Answer: A
Explanation:
Section: Network Intrusion Analysis
NEW QUESTION 46
Which vulnerability type is used to read, write, or erase information from a database?
- A. SQL injection
- B. cross-site request forgery
- C. cross-site scripting
- D. buffer overflow
Answer: A
NEW QUESTION 47
What is the difference between deep packet inspection and stateful inspection?
- A. Stateful inspection verifies data at the transport layer and deep packet inspection verifies data at the application layer
- B. Stateful inspection is more secure due to its complex signatures, and deep packet inspection requires less human intervention.
- C. Deep packet inspection gives insights up to Layer 7, and stateful inspection gives insights only up to Layer 4.
- D. Deep packet inspection is more secure due to its complex signatures, and stateful inspection requires less human intervention.
Answer: D
NEW QUESTION 48
Drag and drop the access control models from the left onto the correct descriptions on the right.
Answer:
Explanation:

NEW QUESTION 49
What should a security analyst consider when comparing inline traffic interrogation with traffic tapping to determine which approach to use in the network?
- A. Tapping interrogations detect and block malicious traffic
- B. Inline interrogation enables viewing a copy of traffic to ensure traffic is in compliance with security policies
- C. Tapping interrogation replicates signals to a separate port for analyzing traffic
- D. Inline interrogation detects malicious traffic but does not block the traffic
Answer: C
Explanation:
Explanation
A network TAP is a simple device that connects directly to the cabling infrastructure to split or copy packets for use in analysis, security, or general network management
NEW QUESTION 50
An engineer received a flood of phishing emails from HR with the source address HRjacobm@companycom.
What is the threat actor in this scenario?
- A. receiver
- B. phishing email
- C. HR
- D. sender
Answer: D
NEW QUESTION 51
Refer to the exhibit. What does this output indicate?
- A. FTP ports are open on the server.
- B. SMB ports are closed on the server.
- C. Email ports are closed on the server.
- D. HTTPS ports are open on the server.
Answer: D
NEW QUESTION 52
An analyst is investigating a host in the network that appears to be communicating to a command and control server on the Internet. After collecting this packet capture, the analyst cannot determine the technique and payload used for the communication.
Which obfuscation technique is the attacker using?
- A. transport layer security encryption
- B. Base64 encoding
- C. SHA-256 hashing
- D. ROT13 encryption
Answer: A
NEW QUESTION 53
......
Best Value Available! Realistic Verified Free 200-201 Exam Questions: https://actualtests.vceengine.com/200-201-vce-test-engine.html
