Cisco 200-201 Practice Test - Questions Answers, Page 19
List of questions
Question 181
Which of these describes SOC metrics in relation to security incidents?
Question 182
What is the difference between the ACK flag and the RST flag?
Question 183
Refer to the exhibit.
An engineer is analyzing a PCAP file after a recent breach An engineer identified that the attacker used an aggressive ARP scan to scan the hosts and found web and SSH servers. Further analysis showed several SSH Server Banner and Key Exchange Initiations. The engineer cannot see the exact data being transmitted over an encrypted channel and cannot identify how the attacker gained access How did the attacker gain access?
Question 184
Refer to the exhibit.
What is occurring within the exhibit?
Question 185
Refer to the exhibit.
Which component is identifiable in this exhibit?
Question 186
An engineer received an alert affecting the degraded performance of a critical server. Analysis showed a heavy CPU and memory load. What is the next step the engineer should take to investigate this resource usage?
Question 187
What is a difference between an inline and a tap mode traffic monitoring?
Question 188
Which regular expression is needed to capture the IP address 192.168.20.232?
Question 189
How does a certificate authority impact security?
Question 190
What is a difference between SIEM and SOAR?
Question