200-201 Dumps Free Test Engine Player Verified Updated [Aug 18, 2023]
Q&As with Explanations Verified & Correct Answers
NEW QUESTION # 114 
Refer to the exhibit. This request was sent to a web application server driven by a database.
Which type of web server attack is represented?
- A. command injection
- B. blind SQL injection
- C. heap memory corruption
- D. parameter manipulation
Answer: B
Explanation:
Section: Host-Based Analysis
NEW QUESTION # 115
Which event is a vishing attack?
- A. obtaining disposed documents from an organization
- B. setting up a rogue access point near a public hotspot
- C. using a vulnerability scanner on a corporate network
- D. impersonating a tech support agent during a phone call
Answer: D
NEW QUESTION # 116
What is an incident response plan?
- A. an organizational approach to security management to ensure a service lifecycle and continuous improvements
- B. an organizational approach to system backup and data archiving aligned to regulations
- C. an organizational approach to disaster recovery and timely restoration ot operational services
- D. an organizational approach to events that could lead to asset loss or disruption of operations
Answer: C
NEW QUESTION # 117
Which attack method intercepts traffic on a switched network?
- A. ARP cache poisoning
- B. DHCP snooping
- C. command and control
- D. denial of service
Answer: A
Explanation:
Explanation
An ARP-based MITM attack is achieved when an attacker poisons the ARP cache of two devices with the MAC address of the attacker's network interface card (NIC). Once the ARP caches have been successfully poisoned, each victim device sends all its packets to the attacker when communicating to the other device and puts the attacker in the middle of the communications path between the two victim devices. It allows an attacker to easily monitor all communication between victim devices. The intent is to intercept and view the information being passed between the two victim devices and potentially introduce sessions and traffic between the two victim devices
NEW QUESTION # 118
An engineer needs to configure network systems to detect command and control communications by decrypting ingress and egress perimeter traffic and allowing network security devices to detect malicious outbound communications. Which technology should be used to accomplish the task?
- A. static IP addresses
- B. digital certificates
- C. cipher suite
- D. signatures
Answer: B
NEW QUESTION # 119
What is the difference between mandatory access control (MAC) and discretionary access control (DAC)?
- A. DAC is the strictest of all levels of control and MAC is object-based access
- B. DAC is controlled by the operating system and MAC is controlled by an administrator
- C. MAC is controlled by the discretion of the owner and DAC is controlled by an administrator
- D. MAC is the strictest of all levels of control and DAC is object-based access
Answer: D
Explanation:
Section: Security Concepts
NEW QUESTION # 120
An engineer receives a security alert that traffic with a known TOR exit node has occurred on the network.
What is the impact of this traffic?
- A. ransomware communicating after infection
- B. data exfiltration
- C. user circumvention of the firewall
- D. users downloading copyrighted content
Answer: C
NEW QUESTION # 121
Which type of evidence supports a theory or an assumption that results from initial evidence?
- A. best
- B. indirect
- C. probabilistic
- D. corroborative
Answer: D
Explanation:
Explanation
Corroborating evidence (or corroboration) is evidence that tends to support a theory or an assumption deduced by some initial evidence. This corroborating evidence confirms the proposition. Cisco CyberOps Associate CBROPS 200-201 Official Cert Guide
NEW QUESTION # 122
Drag and drop the uses on the left onto the type of security system on the right.
Answer:
Explanation:

NEW QUESTION # 123
What is a difference between inline traffic interrogation and traffic mirroring?
- A. Inline traffic copies packets for analysis and security
- B. Traffic mirroring inspects live traffic for analysis and mitigation
- C. Traffic mirroring passes live traffic to a tool for blocking
- D. Inline inspection acts on the original traffic data flow
Answer: D
Explanation:
Inline traffic interrogation analyzes traffic in real time and has the ability to prevent certain traffic from being forwarded Traffic mirroring doesn't pass the live traffic instead it copies traffic from one or more source ports and sends the copied traffic to one or more destinations for analysis by a network analyzer or other monitoring device
NEW QUESTION # 124
An intruder attempted malicious activity and exchanged emails with a user and received corporate information, including email distribution lists. The intruder asked the user to engage with a link in an email.
When the fink launched, it infected machines and the intruder was able to access the corporate network.
Which testing method did the intruder use?
- A. tailgating
- B. social engineering
- C. piggybacking
- D. eavesdropping
Answer: B
NEW QUESTION # 125
Which data type is necessary to get information about source/destination ports?
- A. statistical data
- B. alert data
- C. connectivity data
- D. session data
Answer: C
NEW QUESTION # 126
What is an example of social engineering attacks?
- A. receiving an invitation to the department's weekly WebEx meeting
- B. sending a verbal request to an administrator who knows how to change an account password
- C. receiving an unexpected email from an unknown person with an attachment from someone in the same company
- D. receiving an email from human resources requesting a visit to their secure website to update contact information
Answer: B
NEW QUESTION # 127
One of the objectives of information security is to protect the CIA of information and systems.
What does CIA mean in this context?
- A. confidentiality, integrity, and availability
- B. confidentiality, integrity, and authorization
- C. confidentiality, identity, and availability
- D. confidentiality, identity, and authorization
Answer: A
Explanation:
Section: Security Concepts
NEW QUESTION # 128
What is a benefit of agent-based protection when compared to agentless protection?
- A. It collects and detects all traffic locally
- B. It manages numerous devices simultaneously
- C. It lowers maintenance costs
- D. It provides a centralized platform
Answer: D
NEW QUESTION # 129 
Refer to the exhibit. What information is depicted?
- A. IIS data
- B. network discovery event
- C. IPS event data
- D. NetFlow data
Answer: D
Explanation:
Section: Security Monitoring
NEW QUESTION # 130
How does agentless monitoring differ from agent-based monitoring?
- A. Agent-based monitoring is less intrusive in gathering log data, while agentless requires open ports to fetch the logs
- B. Agentless can access the data via API. while agent-base uses a less efficient method and accesses log data through WMI.
- C. Agent-based monitoring has a lower initial cost for deployment, while agentless monitoring requires resource-intensive deployment.
- D. Agent-based has a possibility to locally filter and transmit only valuable data, while agentless has much higher network utilization
Answer: A
NEW QUESTION # 131
What does cyber attribution identity in an investigation?
- A. threat actors of an attack
- B. exploit of an attack
- C. vulnerabilities exploited
- D. cause of an attack
Answer: A
Explanation:
Explanation/Reference:
NEW QUESTION # 132
Refer to the exhibit.
Drag and drop the element name from the left onto the correct piece of the PCAP file on the right.
Answer:
Explanation:

NEW QUESTION # 133
Which type of evidence supports a theory or an assumption that results from initial evidence?
- A. best
- B. indirect
- C. probabilistic
- D. corroborative
Answer: D
Explanation:
Explanation
NEW QUESTION # 134
An analyst discovers that a legitimate security alert has been dismissed. Which signature caused this impact on network traffic?
- A. true positive
- B. false negative
- C. true negative
- D. false positive
Answer: B
Explanation:
Explanation
A false negative occurs when the security system (usually a WAF) fails to identify a threat. It produces a
"negative" outcome (meaning that no threat has been observed), even though a threat exists.
NEW QUESTION # 135
Drag and drop the security concept on the left onto the example of that concept on the right.
Answer:
Explanation:
NEW QUESTION # 136
At which layer is deep packet inspection investigated on a firewall?
- A. application
- B. transport
- C. data link
- D. internet
Answer: A
NEW QUESTION # 137
Which two pieces of information are collected from the IPv4 protocol header? (Choose two.)
- A. UDP port from which the traffic is sourced
- B. TCP port from which the traffic was sourced
- C. destination IP address of the packet
- D. UDP port to which the traffic is destined
- E. source IP address of the packet
Answer: C,E
NEW QUESTION # 138
......
Verified 200-201 dumps Q&As Latest 200-201 Download: https://www.dumpsking.com/200-201-testking-dumps.html
200-201 Dumps with Free 365 Days Update Fast Exam Updates: https://drive.google.com/open?id=1n3N_vIidOqTiShHC6jd8mQrAISEzghui
