Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the Cisco CyberOps Associate 200-201 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam 200-201 Premium Access

View all detail and faqs for the 200-201 exam


794 Students Passed

89% Average Score

95% Same Questions
Viewing page 5 out of 15 pages
Viewing questions 41-50 out of questions
Questions # 41:

Which items is an end-point application greylist used?

Options:

A.

Items that have been established as malicious

B.

Items that have been established as authorized

C.

Items that have been installed with a baseline

D.

Items before being established as harmful or malicious

Questions # 42:

According to the NIST SP 800-86. which two types of data are considered volatile? (Choose two.)

Options:

A.

swap files

B.

temporary files

C.

login sessions

D.

dump files

E.

free space

Questions # 43:

According to CVSS, which condition is required for attack complexity metrics?

Options:

A.

man-in-the-middle attack

B.

attackers altering any file

C.

complete loss of protection

D.

total loss of availability

Questions # 44:

Refer to the exhibit.

Question # 44

Which attack is being attempted against a web application?

Options:

A.

SQL injection

B.

man-in-the-middle

C.

command injection

D.

denial of service

Questions # 45:

Refer to the exhibit.

Question # 45

What kind of activity occurs in the network?

Options:

A.

TCP reset attack

B.

DNS redirect attack

C.

DNS flood

D.

UDP flood

Questions # 46:

An analyst is investigating a host in the network that appears to be communicating to a command and control server on the Internet. After collecting this packet capture, the analyst cannot determine the technique and payload used for the communication.

Question # 46

Which obfuscation technique is the attacker using?

Options:

A.

Base64 encoding

B.

TLS encryption

C.

SHA-256 hashing

D.

ROT13 encryption

Questions # 47:

What are indicators of attack?

Options:

A.

large numbers of requests for the same file

B.

multiple tog ins from different regions

C.

swells in database read volume

D.

suspicious registry or system file changes

Questions # 48:

Refer to the exhibit.

Question # 48

What must be interpreted from this packet capture?

Options:

A.

IP address 192.168.88 12 is communicating with 192 168 88 149 with a source port 74 to destination port 49098 using TCP protocol

B.

IP address 192.168.88.12 is communicating with 192 168 88 149 with a source port 49098 to destination port 80 using TCP protocol.

C.

IP address 192.168.88.149 is communicating with 192.168 88.12 with a source port 80 to destination port 49098 using TCP protocol.

D.

IP address 192.168.88.149 is communicating with 192.168.88.12 with a source port 49098 to destination port 80 using TCP protocol.

Questions # 49:

Which attack is the network vulnerable to when a stream cipher like RC4 is used twice with the same key?

Options:

A.

forgery attack

B.

plaintext-only attack

C.

ciphertext-only attack

D.

meet-in-the-middle attack

Questions # 50:

Which difficulty occurs when log messages are compared from two devices separated by a Layer 3 device that performs Network Address Translation?

Options:

A.

IP addresses in the log messages match

B.

Timestamps of the log messages are different.

C.

Log messages contain incorrect information

D.

IP addresses in the log messages do not match

Viewing page 5 out of 15 pages
Viewing questions 41-50 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.