Cisco 200-201 Practice Test - Questions Answers, Page 27
List of questions
Question 261
Refer to the exhibit.
Which application-level protocol is being targeted?
Question 262
Which statement describes patch management?
Question 263
Refer to the exhibit.
An attacker gained initial access to the company s network and ran an Nmap scan to advance with the lateral movement technique and to search the sensitive data. Which two elements can an attacker identify from the scan? (Choose two.)
Question 264
Why should an engineer use a full packet capture to investigate a security breach?
Question 265
Refer to the exhibit.
Which technology produced the log?
Question 266
A SOC analyst detected connections to known C&C and port scanning activity to main HR database servers from one of the HR endpoints via Cisco StealthWatch. What are the two next steps of the SOC team according to the NISTSP800-61 incident handling process? (Choose two)
Question 267
Exhibit.
An engineer received a ticket about a slowdown of a web application, Drug analysis of traffic, the engineer suspects a possible attack on a web server. How should the engineer interpret the Wiresharat traffic capture?
Question 268
Refer to the exhibit.
An attacker scanned the server using Nmap.
What did the attacker obtain from this scan?
Question 269
Which classification of cross-site scripting attack executes the payload without storing it for repeated use?
Question 270
An engineer received an alert affecting the degraded performance of a critical server Analysis showed a heavy CPU and memory load What is the next step the engineer should take to investigate this resource usage7
Question