Try Before You Buy

Download a free sample of any of our exam questions and answers

  • 24/7 customer support, Secure shopping site
  • Free One year updates to match real exam scenarios
  • If you failed your exam after buying our products we will refund the full amount back to you.

[Feb-2023] Practice Cisco 350-201 exam. Online Exam Practice Tests with detailed explanations! Pass 350-201 with confidence! [Q25-Q49]

Share

Practice CyberOps Professional 350-201 exam. Online Exam Practice Tests with detailed explanations! Pass 350-201 with confidence!

350-201 - Performing CyberOps Using Cisco Security Technologies Practice Tests 2023 | ExamsTorrent

NEW QUESTION 25
Drag and drop the type of attacks from the left onto the cyber kill chain stages at which the attacks are seen on the right.

Answer:

Explanation:

 

NEW QUESTION 26
A European-based advertisement company collects tracking information from partner websites and stores it on a local server to provide tailored ads. Which standard must the company follow to safeguard the resting data?

  • A. GDPR
  • B. HIPAA
  • C. Sarbanes-Oxley
  • D. PCI-DSS

Answer: A

 

NEW QUESTION 27
An API developer is improving an application code to prevent DDoS attacks. The solution needs to accommodate instances of a large number of API requests coming for legitimate purposes from trustworthy services. Which solution should be implemented?

  • A. Restrict the number of requests based on a calculation of daily averages. If the limit is exceeded, temporarily block access from the IP address and return a 402 HTTP error code.
  • B. Implement REST API Security Essentials solution to automatically mitigate limit exhaustion. If the limit is exceeded, temporarily block access from the service and return a 409 HTTP error code.
  • C. Apply a limit to the number of requests in a given time interval for each API. If the rate is exceeded, block access from the API key temporarily and return a 429 HTTP error code.
  • D. Increase a limit of replies in a given interval for each API. If the limit is exceeded, block access from the API key permanently and return a 450 HTTP error code.

Answer: C

 

NEW QUESTION 28
Refer to the exhibit.

What is occurring in this packet capture?

  • A. DNS tunneling
  • B. TCP flood
  • C. TCP port scan
  • D. DNS flood

Answer: B

 

NEW QUESTION 29
How is a SIEM tool used?

  • A. To collect and analyze security data from network devices and servers and produce alerts
  • B. To collect security data from authentication failures and cyber attacks and forward it for analysis
  • C. To compare security alerts against configured scenarios and trigger system responses
  • D. To search and compare security data against acceptance standards and generate reports for analysis

Answer: A

 

NEW QUESTION 30
Refer to the exhibit.

An employee is a victim of a social engineering phone call and installs remote access software to allow an "MS Support" technician to check his machine for malware. The employee becomes suspicious after the remote technician requests payment in the form of gift cards. The employee has copies of multiple, unencrypted database files, over 400 MB each, on his system and is worried that the scammer copied the files off but has no proof of it. The remote technician was connected sometime between 2:00 pm and 3:00 pm over https. What should be determined regarding data loss between the employee's laptop and the remote technician's system?

  • A. No database files were disclosed
  • B. The database files were disclosed
  • C. The database files integrity was violated
  • D. The database files were intentionally corrupted, and encryption is possible

Answer: C

 

NEW QUESTION 31
An engineer is investigating several cases of increased incoming spam emails and suspicious emails from the HR and service departments. While checking the event sources, the website monitoring tool showed several web scraping alerts overnight. Which type of compromise is indicated?

  • A. dumpster diving
  • B. phishing
  • C. privilege escalation
  • D. social engineering

Answer: D

 

NEW QUESTION 32
What is the impact of hardening machine images for deployment?

  • A. reduces the attack surface
  • B. reduces the steps needed to mitigate threats
  • C. increases the availability of threat alerts
  • D. increases the speed of patch deployment

Answer: A

 

NEW QUESTION 33
A SOC analyst is notified by the network monitoring tool that there are unusual types of internal traffic on IP subnet 103.861.2117.0/24. The analyst discovers unexplained encrypted data files on a computer system that belongs on that specific subnet. What is the cause of the issue?

  • A. DDoS attack
  • B. virus outbreak
  • C. phishing attack
  • D. malware outbreak

Answer: D

 

NEW QUESTION 34
Which action should be taken when the HTTP response code 301 is received from a web application?

  • A. Update the cached header metadata.
  • B. Increase the allowed user limit.
  • C. Confirm the resource's location.
  • D. Modify the session timeout setting.

Answer: A

 

NEW QUESTION 35
Drag and drop the mitigation steps from the left onto the vulnerabilities they mitigate on the right.

Answer:

Explanation:

 

NEW QUESTION 36
Refer to the exhibit.

Cisco Advanced Malware Protection installed on an end-user desktop automatically submitted a low prevalence file to the Threat Grid analysis engine. What should be concluded from this report?

  • A. Threat scores are high, malicious activity is detected, but files have not been modified
  • B. Threat scores are low, malicious ransomware has been detected, and files have been modified
  • C. Threat scores are high, malicious ransomware has been detected, and files have been modified
  • D. Threat scores are low and no malicious file activity is detected

Answer: B

 

NEW QUESTION 37
Which command does an engineer use to set read/write/execute access on a folder for everyone who reaches the resource?

  • A. chmod 774
  • B. chmod 777
  • C. chmod 666
  • D. chmod 775

Answer: B

 

NEW QUESTION 38
An organization installed a new application server for IP phones. An automated process fetched user credentials from the Active Directory server, and the application will have access to on-premises and cloud services. Which security threat should be mitigated first?

  • A. attack using default accounts
  • B. aligning access control policies
  • C. exfiltration during data transfer
  • D. data exposure from backups

Answer: C

 

NEW QUESTION 39
Refer to the exhibit.

Cisco Rapid Threat Containment using Cisco Secure Network Analytics (Stealthwatch) and ISE detects the threat of malware-infected 802.1x authenticated endpoints and places that endpoint into a Quarantine VLAN using Adaptive Network Control policy. Which telemetry feeds were correlated with SMC to identify the malware?

  • A. NetFlow and SNMP
  • B. NetFlow and event data
  • C. event data and syslog data
  • D. SNMP and syslog data

Answer: C

 

NEW QUESTION 40
A security architect is working in a processing center and must implement a DLP solution to detect and prevent any type of copy and paste attempts of sensitive data within unapproved applications and removable devices.
Which technical architecture must be used?

  • A. DLP for data at rest
  • B. DLP for removable data
  • C. DLP for data in motion
  • D. DLP for data in use

Answer: D

Explanation:
Explanation/Reference: https://www.endpointprotector.com/blog/what-is-data-loss-prevention-dlp/

 

NEW QUESTION 41
Drag and drop the phases to evaluate the security posture of an asset from the left onto the activity that happens during the phases on the right.

Answer:

Explanation:

 

NEW QUESTION 42
An organization suffered a security breach in which the attacker exploited a Netlogon Remote Protocol vulnerability for further privilege escalation. Which two actions should the incident response team take to prevent this type of attack from reoccurring? (Choose two.)

  • A. Scan the company server files for known viruses.
  • B. Apply existing patches to the company servers.
  • C. Implement a patch management process.
  • D. Automate antivirus scans of the company servers.
  • E. Define roles and responsibilities in the incident response playbook.

Answer: D,E

 

NEW QUESTION 43
Refer to the exhibit.

Where is the MIME type that should be followed indicated?

  • A. x-content-type-options
  • B. x-test-debug
  • C. x-xss-protection
  • D. strict-transport-security

Answer: B

 

NEW QUESTION 44
Refer to the exhibit.

An engineer is performing static analysis of a file received and reported by a user. Which risk is indicated in this STIX?

  • A. The file is redirecting users to a website that harvests cookies and stored account information.
  • B. The file is redirecting users to the website that is downloading ransomware to encrypt files.
  • C. The file is redirecting users to a website that requests privilege escalations from the user.
  • D. The file is redirecting users to a website that is determining users' geographic location.

Answer: D

 

NEW QUESTION 45
Drag and drop the type of attacks from the left onto the cyber kill chain stages at which the attacks are seen on the right.

Answer:

Explanation:

 

NEW QUESTION 46
A SOC analyst is investigating a recent email delivered to a high-value user for a customer whose network their organization monitors. The email includes a suspicious attachment titled "Invoice RE: 0004489". The hash of the file is gathered from the Cisco Email Security Appliance. After searching Open Source Intelligence, no available history of this hash is found anywhere on the web. What is the next step in analyzing this attachment to allow the analyst to gather indicators of compromise?

  • A. Investigate further in open source repositories using YARA to find matches
  • B. Run and analyze the DLP Incident Summary Report from the Email Security Appliance
  • C. Ask the company to execute the payload for real time analysis
  • D. Obtain a copy of the file for detonation in a sandbox

Answer: D

 

NEW QUESTION 47
An analyst received multiple alerts on the SIEM console of users that are navigating to malicious URLs. The analyst needs to automate the task of receiving alerts and processing the data for further investigations. Three variables are available from the SIEM console to include in an automation script: console_ip, api_token, and reference_set_name. What must be added to this script to receive a successful HTTP response?
#!/usr/bin/python import sys import requests

  • A. console_ip, api_token
  • B. {1}, {3}
  • C. {1}, {2}
  • D. console_ip, reference_set_name

Answer: A

 

NEW QUESTION 48
What is needed to assess risk mitigation effectiveness in an organization?

  • A. cost-effectiveness of control measures
  • B. updated list of vulnerable systems
  • C. compliance with security standards
  • D. analysis of key performance indicators

Answer: A

 

NEW QUESTION 49
......

The best 350-201 exam study material and preparation tool is here: https://pass4sure.examstorrent.com/350-201-exam-dumps-torrent.html