Cisco 200-201 Practice Test - Questions Answers, Page 36

List of questions
Question 351

What are two differences and benefits of packet filtering, stateful firewalling, and deep packet inspections? (Choose two.)
Question 352

Refer to the exhibit.
Refer to the exhibit. A network engineer received a report that a host is communicating with unknown domains on the internet. The network engineer collected packet capture but could not determine the technique or the payload used. What technique is the attacker using?
Question 353

Refer to the exhibit.
Refer to the exhibit. An engineer received a ticket to analyze unusual network traffic. What is occurring?
Question 354

What is the advantage of agent-based protection compared to agentless protection?
Question 355

A suspicious user opened a connection from a compromised host inside an organization. Traffic was going through a router and the network administrator was able to identify this flow. The admin was following 5-tuple to collect needed data. Which information was gathered based on this approach?
Question 356

Refer to the exhibit.
Refer to the exhibit. A SOC analyst is examining the Windows security logs of one of the endpoints. What is the possible reason for this event log?
Question 357

An analyst see that this security alert 'Default-Botnet-Communication-Detection-By-Endpoint' has been raised from the IPS. The analyst checks and finds that an endpoint communicates to the C&C. How must an impact from this event be categorized?
Question 358

What is the difference between authentication and authorization?
Question 359

Which risk approach eliminates activities posing a risk exposure?
Question 360

Which of these describes volatile evidence?
Question