Cisco 200-201 Practice Test - Questions Answers, Page 24
List of questions
Question 231

When an event is investigated, which type of data provides the investigate capability to determine if data exfiltration has occurred?
Question 232

What is the difference between deep packet inspection and stateful inspection?
Question 233

What is obtained using NetFlow?
Question 234

How does statistical detection differ from rule-based detection?
Question 235

Refer to the exhibit.
What must be interpreted from this packet capture?
Question 236

Refer to the exhibit.
Which field contains DNS header information if the payload is a query or a response?
Question 237

Refer to the exhibit.
What is occurring?
Question 238

What is the difference between vulnerability and risk?
Question 239

An engineer received a flood of phishing emails from HR with the source address HRjacobm@companycom. What is the threat actor in this scenario?
Question 240

Refer to the exhibit.
A security analyst is investigating unusual activity from an unknown IP address Which type of evidence is this file1?
Question