Cisco 200-201 Practice Test - Questions Answers, Page 27
List of questions
Question 261

Refer to the exhibit.
Which application-level protocol is being targeted?
Question 262

Which statement describes patch management?
Question 263

Refer to the exhibit.
An attacker gained initial access to the company s network and ran an Nmap scan to advance with the lateral movement technique and to search the sensitive data. Which two elements can an attacker identify from the scan? (Choose two.)
Question 264

Why should an engineer use a full packet capture to investigate a security breach?
Question 265

Refer to the exhibit.
Which technology produced the log?
Question 266

A SOC analyst detected connections to known C&C and port scanning activity to main HR database servers from one of the HR endpoints via Cisco StealthWatch. What are the two next steps of the SOC team according to the NISTSP800-61 incident handling process? (Choose two)
Question 267

Exhibit.
An engineer received a ticket about a slowdown of a web application, Drug analysis of traffic, the engineer suspects a possible attack on a web server. How should the engineer interpret the Wiresharat traffic capture?
Question 268

Refer to the exhibit.
An attacker scanned the server using Nmap.
What did the attacker obtain from this scan?
Question 269

Which classification of cross-site scripting attack executes the payload without storing it for repeated use?
Question 270

An engineer received an alert affecting the degraded performance of a critical server Analysis showed a heavy CPU and memory load What is the next step the engineer should take to investigate this resource usage7
Question