Cisco 200-201 Practice Test - Questions Answers, Page 32
List of questions
Question 311

A network engineer noticed in the NetFlow report that internal hosts are sending many DNS requests to external DNS servers A SOC analyst checked the endpoints and discovered that they are infected and became part of the botnet Endpoints are sending multiple DNS requests but with spoofed IP addresses of valid external sources What kind of attack are infected endpoints involved in1?
Question 312

Which items is an end-point application greylist used?
Question 313

Which type of data is used to detect anomalies in the network?
Question 314

An engineer must investigate suspicious connections. Data has been gathered using a tcpdump command on a Linux device and saved as sandboxmatware2022-12-22.pcaps file. The engineer is trying to open the tcpdump in the Wireshark tool. What is the expected result?
Question 315

Refer to the exhibit.
What does this Cuckoo sandbox report indicate?
Question 316

A security engineer must protect the company from known issues that trigger adware. Recently new incident has been raised that could harm the system. Which security concepts are present in this scenario?
Question 317

An engineer configured regular expression ''.''\.(pd][Oo][Cc)|[Xx][LI][Ss]|[Pp][Pp][Tt]) HTTP/1 .[01]' on Cisco ASA firewall. What does this regular expression do?
Question 318

What is a comparison between rule-based and statistical detection?
Question 319

What is a comparison between rule-based and statistical detection?
Question 320

Refer to the exhibit.
Which attack is being attempted against a web application?
Question