Cisco 200-201 Practice Test - Questions Answers, Page 36
List of questions
Question 351
What are two differences and benefits of packet filtering, stateful firewalling, and deep packet inspections? (Choose two.)
Question 352
Refer to the exhibit.
Refer to the exhibit. A network engineer received a report that a host is communicating with unknown domains on the internet. The network engineer collected packet capture but could not determine the technique or the payload used. What technique is the attacker using?
Question 353
Refer to the exhibit.
Refer to the exhibit. An engineer received a ticket to analyze unusual network traffic. What is occurring?
Question 354
What is the advantage of agent-based protection compared to agentless protection?
Question 355
A suspicious user opened a connection from a compromised host inside an organization. Traffic was going through a router and the network administrator was able to identify this flow. The admin was following 5-tuple to collect needed data. Which information was gathered based on this approach?
Question 356
Refer to the exhibit.
Refer to the exhibit. A SOC analyst is examining the Windows security logs of one of the endpoints. What is the possible reason for this event log?
Question 357
An analyst see that this security alert 'Default-Botnet-Communication-Detection-By-Endpoint' has been raised from the IPS. The analyst checks and finds that an endpoint communicates to the C&C. How must an impact from this event be categorized?
Question 358
What is the difference between authentication and authorization?
Question 359
Which risk approach eliminates activities posing a risk exposure?
Question 360
Which of these describes volatile evidence?
Question