Cisco 200-201 Practice Test - Questions Answers, Page 24
List of questions
Question 231
When an event is investigated, which type of data provides the investigate capability to determine if data exfiltration has occurred?
Question 232
What is the difference between deep packet inspection and stateful inspection?
Question 233
What is obtained using NetFlow?
Question 234
How does statistical detection differ from rule-based detection?
Question 235
Refer to the exhibit.
What must be interpreted from this packet capture?
Question 236
Refer to the exhibit.
Which field contains DNS header information if the payload is a query or a response?
Question 237
Refer to the exhibit.
What is occurring?
Question 238
What is the difference between vulnerability and risk?
Question 239
An engineer received a flood of phishing emails from HR with the source address HRjacobm@companycom. What is the threat actor in this scenario?
Question 240
Refer to the exhibit.
A security analyst is investigating unusual activity from an unknown IP address Which type of evidence is this file1?
Question