DumpsQuestion 200-201 dumps & CyberOps Associate Sure Practice with 452 Questions
New 200-201 Exam Questions| Real 200-201 Dumps
NEW QUESTION # 35
Which security principle is violated by running all processes as root or administrator?
- A. role-based access control
- B. separation of duties
- C. trusted computing base
- D. principle of least privilege
Answer: D
Explanation:
Section: Security Concepts
NEW QUESTION # 36
According to the September 2020 threat intelligence feeds a new malware called Egregor was introduced and used in many attacks. Distnbution of Egregor is pnmanly through a Cobalt Strike that has been installed on victim's workstations using RDP exploits Malware exfiltrates the victim's data to a command and control server. The data is used to force victims pay or lose it by publicly releasing it. Which type of attack is described?
- A. ransomware attack
- B. insider threat
- C. whale-phishing
- D. malware attack
Answer: A
Explanation:
Ransomware is a type of malware that encrypts the victim's data and demands a ransom for the decryption key. The attacker may also threaten to publish or delete the data if the ransom is not paid. In this case, the Egregor malware is distributed through a Cobalt Strike, which is a penetration testing tool that can be used to deploy payloads on compromised systems. The malware exfiltrates the victim's data to a command and control server and uses it as leverage to extort money from the victim. Reference:= Cisco Cybersecurity Operations Fundamentals, Module 1: Security Concepts, Lesson 1.3: Common Network Application Operations and Attacks, Topic 1.3.3: Malware Attacks
NEW QUESTION # 37
Drag and drop the definition from the left onto the phase on the right to classify intrusion events according to the Cyber Kill Chain model.
Answer:
Explanation:

NEW QUESTION # 38
What is data encapsulation?
- A. Multiple hosts can be supported with only a few public IP addresses.
- B. Data is encrypted backwards, which makes it unusable.
- C. Browsing history is erased automatically with every session.
- D. The protocol of the sending host adds additional data to the packet header.
Answer: D
Explanation:
Data encapsulation is a process in networking where the protocol stack of the sending host adds headers (and sometimes trailers) to the data.
Each layer of the OSI or TCP/IP model adds its own header to the data as it passes down the layers, preparing it for transmission over the network.
For example, in the TCP/IP model, data starts at the application layer and is encapsulated at each subsequent layer (Transport, Internet, and Network Access) before being transmitted.
This encapsulation ensures that the data is correctly formatted and routed to its destination, where the headers are stripped off in reverse order by the receiving host.
Reference:
Networking Fundamentals by Cisco
OSI Model and Data Encapsulation Process
Understanding TCP/IP Encapsulation
NEW QUESTION # 39
Refer to the exhibit.
Refer to the exhibit. The figure shows an X 509 certificate. Which field represents the digital cryptographic algorithm used by the issuer to sign the certificate?
- A. Fingerprints
- B. Log Operator
- C. Signature Algorithm
- D. Timestamp
Answer: C
NEW QUESTION # 40
According to CVSS, which condition is required for attack complexity metrics?
- A. complete loss of protection
- B. total loss of availability
- C. attackers altering any file
- D. man-in-the-middle attack
Answer: D
NEW QUESTION # 41
What is the difference between statistical detection and rule-based detection models?
- A. Rule-based detection involves the collection of data in relation to the behavior of legitimate users over a period of time
- B. Rule-based detection defines legitimate data of users over a period of time and statistical detection defines it on an IF/THEN basis
- C. Statistical detection involves the evaluation of an object on its intended actions before it executes that behavior
- D. Statistical detection defines legitimate data of users over a period of time and rule-based detection defines it on an IF/THEN basis
Answer: D
Explanation:
Statistical detection involves collecting data over time to define what is considered normal behavior or legitimate data for users or systems. It then uses statistical analysis to identify abnormal behavior that could indicate a security incident. Rule-based detection uses predefined rules or patterns that are based on known threats or vulnerabilities - it operates on an IF/THEN basis where if certain conditions are met then an alert is triggered. References := Cisco Cybersecurity Operations Fundamentals
NEW QUESTION # 42
Refer to the exhibit.
Drag and drop the element name from the left onto the correct piece of the PCAP file on the right.
Answer:
Explanation:

NEW QUESTION # 43
Which statement describes patch management?
- A. scanning servers and workstations for missing patches and vulnerabilities
- B. process of appropriate distribution of system or software updates
- C. managing and keeping previous patches lists documented for audit purposes
- D. workflow of distributing mitigations of newly found vulnerabilities
Answer: B
Explanation:
Patch management is the process of distributing and managing updates to software and systems. These updates can include patches for security vulnerabilities, bug fixes, and enhancements to improve performance or add new features. It ensures that systems are up-to-date, secure, and performing optimally. Reference:= Cisco Cybersecurity Training
NEW QUESTION # 44
Refer to the exhibit.
Which type of log is displayed?
- A. proxy
- B. NetFlow
- C. sys
- D. IDS
Answer: D
Explanation:
You also see the 5-tuple in IPS events, NetFlow records, and other event data. In fact, on the exam you may need to differentiate between a firewall log versus a traditional IPS or IDS event. One of the things to remember is that traditional IDS and IPS use signatures, so an easy way to differentiate is by looking for a signature ID (SigID). If you see a signature ID, then most definitely the event is a traditional IPS or IDS event.
NEW QUESTION # 45
Which statement describes indicators of attack?
- A. internal hosts communicate with countries outside of the business range.
- B. Critical patches are missing.
- C. A malicious file is detected by the AV software.
- D. Phishing attempts on an organization are blocked by mall AV.
Answer: A
Explanation:
Indicators of Attack (IoA) refer to observable behaviors or artifacts that suggest a security breach or ongoing attack.
When internal hosts communicate with countries outside the business range, it may indicate data exfiltration or command-and-control communication to an external threat actor.
Unlike Indicators of Compromise (IoC) which indicate that a system has already been compromised, IoAs are often used to identify malicious activity in its early stages.
Monitoring for unusual outbound connections is a crucial aspect of detecting advanced persistent threats (APTs) and other sophisticated attacks.
Reference:
Difference Between Indicators of Compromise and Indicators of Attack
Cyber Threat Detection Using Indicators of Attack
Network Monitoring for Anomalous Behavior
NEW QUESTION # 46
What is the difference between deep packet inspection and stateful inspection?
- A. Deep packet inspection is more secure due to its complex signatures, and stateful inspection requires less human intervention.
- B. Deep packet inspection gives insights up to Layer 7, and stateful inspection gives insights only up to Layer 4.
- C. Stateful inspection verifies data at the transport layer and deep packet inspection verifies data at the application layer
- D. Stateful inspection is more secure due to its complex signatures, and deep packet inspection requires less human intervention.
Answer: B
Explanation:
Deep packet inspection (DPI) analyzes the data part (and possibly also the header) of a packet as it passes an inspection point, searching for protocol non-compliance, viruses, spam, intrusions, or defined criteria to decide whether the packet may pass or if it needs to be routed to a different destination. Stateful inspection, on the other hand, tracks the state of active connections and determines which network packets to allow through the firewall. While stateful inspection tracks the state of connections (Layer 4 - transport layer), DPI goes further by examining the payload of the packet (Layer 7 - application layer).
NEW QUESTION # 47
What is a difference between SOAR and SIEM?
- A. SOAR receives information from a single platform and delivers it to a SIEM
- B. SIEM applications are used for threat and vulnerability management, but SOAR platforms are not
- C. SOAR platforms are used for threat and vulnerability management, but SIEM applications are not
- D. SIEM receives information from a single platform and delivers it to a SOAR
Answer: C
NEW QUESTION # 48
Which two elements are assets in the role of attribution in an investigation? (Choose two.)
- A. context
- B. laptop
- C. session
- D. firewall logs
- E. threat actor
Answer: B,E
Explanation:
In the context of cybersecurity, an asset is anything that has value to the organization, its business operations and their continuity, including data and physical devices. In the role of attribution in an investigation, which is the process of associating an action or event with a particular individual or entity, certain assets are particularly relevant. A laptop can be an asset because it may contain data or clues that can help trace the origin of a cyber attack. Similarly, identifying the threat actor (E) is crucial for attribution, as it involves understanding who is behind the attack and their motives, which can be essential for preventing future attacks and for legal proceedings.
Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS)1.
NEW QUESTION # 49
What describes the concept of data consistently and readily being accessible for legitimate users?
- A. integrity
- B. confidentiality
- C. availability
- D. accessibility
Answer: C
NEW QUESTION # 50
......
200-201 Braindumps – 200-201 Questions to Get Better Grades: https://examsdocs.dumpsquestion.com/200-201-exam-dumps-collection.html