Cisco 200-201 Practice Test - Questions Answers, Page 11
List of questions
Question 101
Refer to the exhibit.
Which event is occurring?
Question 102
Refer to the exhibit.
In which Linux log file is this output found?
Question 103
An engineer runs a suspicious file in a sandbox analysis tool to see the outcome. The analysis report shows that outbound callouts were made post infection.
Which two pieces of information from the analysis report are needed to investigate the callouts? (Choose two.)
Question 104
An analyst is exploring the functionality of different operating systems.
What is a feature of Windows Management Instrumentation that must be considered when deciding on an operating system?
Question 105
What causes events on a Windows system to show Event Code 4625 in the log messages?
Question 106
Refer to the exhibit.
What does the message indicate?
Question 107
Refer to the exhibit.
This request was sent to a web application server driven by a database. Which type of web server attack is represented?
Question 108
A SOC analyst is investigating an incident that involves a Linux system that is identifying specific sessions. Which identifier tracks an active program?
Question 109
An offline audit log contains the source IP address of a session suspected to have exploited a vulnerability resulting in system compromise.
Which kind of evidence is this IP address?
Question 110
Which system monitors local system operation and local network access for violations of a security policy?
Question