Cisco 200-201 Practice Test - Questions Answers, Page 11

List of questions
Question 101

Refer to the exhibit.
Which event is occurring?
Question 102

Refer to the exhibit.
In which Linux log file is this output found?
Question 103

An engineer runs a suspicious file in a sandbox analysis tool to see the outcome. The analysis report shows that outbound callouts were made post infection.
Which two pieces of information from the analysis report are needed to investigate the callouts? (Choose two.)
Question 104

An analyst is exploring the functionality of different operating systems.
What is a feature of Windows Management Instrumentation that must be considered when deciding on an operating system?
Question 105

What causes events on a Windows system to show Event Code 4625 in the log messages?
Question 106

Refer to the exhibit.
What does the message indicate?
Question 107

Refer to the exhibit.
This request was sent to a web application server driven by a database. Which type of web server attack is represented?
Question 108

A SOC analyst is investigating an incident that involves a Linux system that is identifying specific sessions. Which identifier tracks an active program?
Question 109

An offline audit log contains the source IP address of a session suspected to have exploited a vulnerability resulting in system compromise.
Which kind of evidence is this IP address?
Question 110

Which system monitors local system operation and local network access for violations of a security policy?
Question