Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the Cisco CyberOps Associate 200-201 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam 200-201 Premium Access

View all detail and faqs for the 200-201 exam


794 Students Passed

89% Average Score

95% Same Questions
Viewing page 14 out of 15 pages
Viewing questions 131-140 out of questions
Questions # 131:

An organization's security team has detected network spikes coming from the internal network. An investigation has concluded that the spike in traffic was from intensive network scanning How should the analyst collect the traffic to isolate the suspicious host?

Options:

A.

by most active source IP

B.

by most used ports

C.

based on the protocols used

D.

based on the most used applications

Questions # 132:

An engineer is sharing folders and files with different departments and got this error: "No such file or directory". What must the engineer verify next?

Options:

A.

memory allocation

B.

symlinks

C.

permission

D.

disk space

Questions # 133:

Which regex matches only on all lowercase letters?

Options:

A.

[a−z]+

B.

[^a−z]+

C.

a−z+

D.

a*z+

Questions # 134:

What is the role of indicator of compromise in an investigation?

Options:

A.

It helps answer the question of why the attack took place.

B.

It identifies potentially malicious activity on a system or network.

C.

It is nonforensic data, which is easy to detect.

D.

It describes what and why something happened.

Questions # 135:

What is the principle of defense-in-depth?

Options:

A.

Agentless and agent-based protection for security are used.

B.

Several distinct protective layers are involved.

C.

Access control models are involved.

D.

Authentication, authorization, and accounting mechanisms are used.

Questions # 136:

An engineer received an alert affecting the degraded performance of a critical server. Analysis showed a heavy CPU and memory load. What is the next step the engineer should take to investigate this resource usage?

Options:

A.

Run "ps -d" to decrease the priority state of high load processes to avoid resource exhaustion.

B.

Run "ps -u" to find out who executed additional processes that caused a high load on a server.

C.

Run "ps -ef" to understand which processes are taking a high amount of resources.

D.

Run "ps -m" to capture the existing state of daemons and map required processes to find the gap.

Questions # 137:

An engineer needs to have visibility on TCP bandwidth usage, response time, and latency, combined with deep packet inspection to identify unknown software by its network traffic flow. Which two features of Cisco Application Visibility and Control should the engineer use to accomplish this goal? (Choose two.)

Options:

A.

management and reporting

B.

traffic filtering

C.

adaptive AVC

D.

metrics collection and exporting

E.

application recognition

Questions # 138:

An analyst is using the SIEM platform and must extract a custom property from a Cisco device and capture the phrase, "File: Clean." Which regex must the analyst import?

Options:

A.

File: Clean

B.

^Parent File Clean$

C.

File: Clean (.*)

D.

^File: Clean$

Questions # 139:

Question # 139

Refer to the exhibit. What occurred on this system based on this output?

Options:

A.

A user connected to the system using remote access VPN.

B.

A user created a new HTTP session using the SHA256 hashing algorithm.

C.

A user connected to the system after 450 attempts.

D.

A user connected to the system using SSH using source port 55796.

Questions # 140:

What is the key difference between mandatory access control (MAC) and discretionary access control (DAC)?

Options:

A.

DAC is controlled by the OS, and MAC is controlled by the owner of the access list.

B.

DAC is the most strict access control, and MAC is object-based access.

C.

MAC is controlled by the OS, and DAC is controlled by the owner of the access list.

D.

MAC is the most strict access control, and DAC is object-based access.

Viewing page 14 out of 15 pages
Viewing questions 131-140 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.