ExamGecko
Home / Cisco / 200-201 / List of questions
Ask Question

Cisco 200-201 Practice Test - Questions Answers, Page 36

Add to Whishlist

List of questions

Question 351

Report Export Collapse

What are two differences and benefits of packet filtering, stateful firewalling, and deep packet inspections? (Choose two.)

Become a Premium Member for full access
  Unlock Premium Member

Question 352

Report Export Collapse

Refer to the exhibit.

Cisco 200-201 image Question 21 63879656099020870715642

Refer to the exhibit. A network engineer received a report that a host is communicating with unknown domains on the internet. The network engineer collected packet capture but could not determine the technique or the payload used. What technique is the attacker using?

Become a Premium Member for full access
  Unlock Premium Member

Question 353

Report Export Collapse

Refer to the exhibit.

Cisco 200-201 image Question 22 63879656099052120435160

Refer to the exhibit. An engineer received a ticket to analyze unusual network traffic. What is occurring?

Become a Premium Member for full access
  Unlock Premium Member

Question 354

Report Export Collapse

What is the advantage of agent-based protection compared to agentless protection?

Become a Premium Member for full access
  Unlock Premium Member

Question 355

Report Export Collapse

A suspicious user opened a connection from a compromised host inside an organization. Traffic was going through a router and the network administrator was able to identify this flow. The admin was following 5-tuple to collect needed data. Which information was gathered based on this approach?

Become a Premium Member for full access
  Unlock Premium Member

Question 356

Report Export Collapse

Refer to the exhibit.

Cisco 200-201 image Question 25 63879656099067744518798

Refer to the exhibit. A SOC analyst is examining the Windows security logs of one of the endpoints. What is the possible reason for this event log?

Become a Premium Member for full access
  Unlock Premium Member

Question 357

Report Export Collapse

An analyst see that this security alert 'Default-Botnet-Communication-Detection-By-Endpoint' has been raised from the IPS. The analyst checks and finds that an endpoint communicates to the C&C. How must an impact from this event be categorized?

Become a Premium Member for full access
  Unlock Premium Member

Question 358

Report Export Collapse

What is the difference between authentication and authorization?

Become a Premium Member for full access
  Unlock Premium Member

Question 359

Report Export Collapse

Which risk approach eliminates activities posing a risk exposure?

Become a Premium Member for full access
  Unlock Premium Member

Question 360

Report Export Collapse

Which of these describes volatile evidence?

Become a Premium Member for full access
  Unlock Premium Member
Total 378 questions
Go to page: of 38