Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the Cisco CyberOps Associate 200-201 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam 200-201 Premium Access

View all detail and faqs for the 200-201 exam


794 Students Passed

89% Average Score

95% Same Questions
Viewing page 13 out of 15 pages
Viewing questions 121-130 out of questions
Questions # 121:

Refer to the exhibit.

Question # 121

A security analyst is investigating unusual activity from an unknown IP address Which type of evidence is this file1?

Options:

A.

indirect evidence

B.

best evidence

C.

corroborative evidence

D.

direct evidence

Questions # 122:

What is the difference between authentication and authorization?

Options:

A.

Authorization is used by a server when the server needs to know exactly who is accessing resources, and authentication is a process by which a server determines the permissions.

B.

Authorization allows an engineer to control the user access level privileges to the router, and authentication is the process of giving the user-specific permissions.

C.

Authentication is coupled with authorization so that the server knows who the requestor is, and authorization is used by a requestor that knows the server.

D.

Authentication allows an engineer to identify who can connect to a router, and authorization is the function of specifying access rights and privileges to resources.

Questions # 123:

What is a difference between SIEM and SOAR?

Options:

A.

SOAR predicts and prevents security alerts, while SIEM checks attack patterns and applies the mitigation.

B.

SlEM's primary function is to collect and detect anomalies, while SOAR is more focused on security operations automation and response.

C.

SIEM predicts and prevents security alerts, while SOAR checks attack patterns and applies the mitigation.

D.

SOAR's primary function is to collect and detect anomalies, while SIEM is more focused on security operations automation and response.

Questions # 124:

Which statement describes patch management?

Options:

A.

scanning servers and workstations for missing patches and vulnerabilities

B.

managing and keeping previous patches lists documented for audit purposes

C.

process of appropriate distribution of system or software updates

D.

workflow of distributing mitigations of newly found vulnerabilities

Questions # 125:

What is the difference between the rule-based detection when compared to behavioral detection?

Options:

A.

Rule-Based detection is searching for patterns linked to specific types of attacks, while behavioral is identifying per signature.

B.

Rule-Based systems have established patterns that do not change with new data, while behavioral changes.

C.

Behavioral systems are predefined patterns from hundreds of users, while Rule-Based only flags potentially abnormal patterns using signatures.

D.

Behavioral systems find sequences that match a particular attack signature, while Rule-Based identifies potential attacks.

Questions # 126:

A security engineer notices confidential data being exfiltrated to a domain "Ranso4134-mware31-895" address that is attributed to a known advanced persistent threat group The engineer discovers that the activity is part of a real attack and not a network misconfiguration. Which category does this event fall under as defined in the Cyber Kill Chain?

Options:

A.

reconnaissance

B.

delivery

C.

action on objectives

D.

weaponization

Questions # 127:

What specific type of analysis is assigning values to the scenario to see expected outcomes?

Options:

A.

deterministic

B.

exploratory

C.

probabilistic

D.

descriptive

Questions # 128:

Drag and drop the access control models from the left onto the correct descriptions on the right.

Question # 128

Options:

Questions # 129:

Refer to the exhibit.

Question # 129

What information is depicted?

Options:

A.

IIS data

B.

NetFlow data

C.

network discovery event

D.

IPS event data

Questions # 130:

A large load of data is being transferred to an external destination via UDP 53 port. Which obfuscation technique is used?

Options:

A.

proxied traffic

B.

C&C connection

C.

data masking

D.

DNS tunneling

Viewing page 13 out of 15 pages
Viewing questions 121-130 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.