Get Apr-2023 updated 350-201 Certification Exam Sample Questions
350-201 Study Guide Cover to Cover as Literally
Conclusion
By using verified training materials dedicated to the topics tested in the Cisco 350-201 exam, the candidates will have no problems in passing it with flying colors. Even though the test preparation process might seem difficult, students should understand that this certification makes them valuable crewmen in any CyberOps team and helps them get a salary that is above the market’s average.
NEW QUESTION 27
Where do threat intelligence tools search for data to identify potential malicious IP addresses, domain names, and URLs?
- A. Internet
- B. customer data
- C. internal database
- D. internal cloud
Answer: A
NEW QUESTION 28
Which command does an engineer use to set read/write/execute access on a folder for everyone who reaches the resource?
- A. chmod 775
- B. chmod 666
- C. chmod 774
- D. chmod 777
Answer: D
NEW QUESTION 29
A company recently completed an internal audit and discovered that there is CSRF vulnerability in 20 of its hosted applications. Based on the audit, which recommendation should an engineer make for patching?
- A. Update software to patch third-party software
- B. Fix applications according to the risk scores
- C. Identify the business applications running on the assets
- D. Validate CSRF by executing exploits within Metasploit
Answer: B
NEW QUESTION 30
Refer to the exhibit.
Where are the browser page rendering permissions displayed?
- A. x-xss-protection
- B. x-content-type-options
- C. x-frame-options
- D. x-test-debug
Answer: B
NEW QUESTION 31
A security engineer discovers that a spreadsheet containing confidential information for nine of their employees was fraudulently posted on a competitor's website. The spreadsheet contains names, salaries, and social security numbers. What is the next step the engineer should take in this investigation?
- A. Check incoming and outgoing communications to identify spoofed emails.
- B. Determine if there is internal knowledge of this incident.
- C. Disconnect the network from Internet access to stop the phishing threats and regain control.
- D. Engage the legal department to explore action against the competitor that posted the spreadsheet.
Answer: D
NEW QUESTION 32
Refer to the exhibit.
A security analyst needs to investigate a security incident involving several suspicious connections with a possible attacker. Which tool should the analyst use to identify the source IP of the offender?
- A. firewall manager
- B. packet sniffer
- C. malware analysis
- D. SIEM
Answer: B
NEW QUESTION 33
Refer to the exhibit.
The Cisco Secure Network Analytics (Stealthwatch) console alerted with "New Malware Server Discovered" and the IOC indicates communication from an end-user desktop to a Zeus C&C Server. Drag and drop the actions that the analyst should take from the left into the order on the right to investigate and remediate this IOC.
Answer:
Explanation:
NEW QUESTION 34
A patient views information that is not theirs when they sign in to the hospital's online portal. The patient calls the support center at the hospital but continues to be put on hold because other patients are experiencing the same issue. An incident has been declared, and an engineer is now on the incident bridge as the CyberOps Tier 3 Analyst. There is a concern about the disclosure of PII occurring in real-time. What is the first step the analyst should take to address this incident?
- A. Contact the third-party handling provider to respond to the incident as critical
- B. Review system and application logs to identify errors in the portal code
- C. Evaluate visibility tools to determine if external access resulted in tampering
- D. Turn off all access to the patient portal to secure patient records
Answer: D
NEW QUESTION 35
The incident response team was notified of detected malware. The team identified the infected hosts, removed the malware, restored the functionality and data of infected systems, and planned a company meeting to improve the incident handling capability. Which step was missed according to the NIST incident handling guide?
- A. Install IPS software
- B. Perform vulnerability assessment
- C. Contain the malware
- D. Determine the escalation path
Answer: B
Explanation:
Explanation/Reference:
NEW QUESTION 36
A security analyst receives an escalation regarding an unidentified connection on the Accounting A1 server within a monitored zone. The analyst pulls the logs and discovers that a Powershell process and a WMI tool process were started on the server after the connection was established and that a PE format file was created in the system directory. What is the next step the analyst should take?
- A. Perform behavioral analysis of the processes on an isolated workstation and perform cleaning procedures if the file is malicious
- B. Isolate the server and perform forensic analysis of the file to determine the type and vector of a possible attack
- C. Identify the server owner through the CMDB and contact the owner to determine if these were planned and identifiable activities
- D. Review the server backup and identify server content and data criticality to assess the intrusion risk
Answer: D
NEW QUESTION 37
Employees report computer system crashes within the same week. An analyst is investigating one of the computers that crashed and discovers multiple shortcuts in the system's startup folder. It appears that the shortcuts redirect users to malicious URLs. What is the next step the engineer should take to investigate this case?
- A. Identify affected systems
- B. Investigate the malicious URLs
- C. Check the audit logs
- D. Remove the shortcut files
Answer: A
NEW QUESTION 38
Refer to the exhibit.
Which data format is being used?
- A. JSON
- B. XML
- C. CSV
- D. HTML
Answer: D
NEW QUESTION 39 
Refer to the exhibit. An engineer is investigating a case with suspicious usernames within the active directory.
After the engineer investigates and cross-correlates events from other sources, it appears that the 2 users are privileged, and their creation date matches suspicious network traffic that was initiated from the internal network 2 days prior. Which type of compromise is occurring?
- A. compromised root access
- B. compromised database tables
- C. compromised network
- D. compromised insider
Answer: C
NEW QUESTION 40
Refer to the exhibit.
An engineer is investigating a case with suspicious usernames within the active directory. After the engineer investigates and cross-correlates events from other sources, it appears that the 2 users are privileged, and their creation date matches suspicious network traffic that was initiated from the internal network 2 days prior. Which type of compromise is occurring?
- A. compromised root access
- B. compromised database tables
- C. compromised network
- D. compromised insider
Answer: C
NEW QUESTION 41 
Refer to the exhibit. Cisco Rapid Threat Containment using Cisco Secure Network Analytics (Stealthwatch) and ISE detects the threat of malware-infected 802.1x authenticated endpoints and places that endpoint into a Quarantine VLAN using Adaptive Network Control policy. Which telemetry feeds were correlated with SMC to identify the malware?
- A. NetFlow and SNMP
- B. event data and syslog data
- C. NetFlow and event data
- D. SNMP and syslog data
Answer: B
NEW QUESTION 42
Refer to the exhibit.
What is the connection status of the ICMP event?
- A. blocked by an intrusion policy rule
- B. allowed in the default action
- C. blocked by a configured access policy rule
- D. allowed by a configured access policy rule
Answer: D
NEW QUESTION 43
Refer to the exhibit.
How are tokens authenticated when the REST API on a device is accessed from a REST API client?
- A. The token is obtained before providing a password. The REST client provides access to a resource using the access token. The REST API encrypts the access token and gives access to the resource.
- B. The token is obtained before providing a password. The REST API provides resource access, refreshes tokens, and returns them to the REST client. The REST client requests access to a resource using the access token.
- C. The token is obtained by providing a password. The REST API requests access to a resource using the access token, validates the access token, and gives access to the resource.
- D. The token is obtained by providing a password. The REST client requests access to a resource using the access token. The REST API validates the access token and gives access to the resource.
Answer: A
NEW QUESTION 44
Refer to the exhibit.
The Cisco Secure Network Analytics (Stealthwatch) console alerted with "New Malware Server Discovered" and the IOC indicates communication from an end-user desktop to a Zeus C&C Server. Drag and drop the actions that the analyst should take from the left into the order on the right to investigate and remediate this IOC.
Answer:
Explanation:
NEW QUESTION 45
An engineer is analyzing a possible compromise that happened a week ago when the company database servers unexpectedly went down. The analysis reveals that attackers tampered with Microsoft SQL Server Resolution Protocol and launched a DDoS attack. The engineer must act quickly to ensure that all systems are protected. Which two tools should be used to detect and mitigate this type of future attack? (Choose two.)
- A. firewall
- B. autopsy
- C. SHA512
- D. IPS
- E. Wireshark
Answer: A,E
NEW QUESTION 46
Refer to the exhibit.
How must these advisories be prioritized for handling?
- A. Vulnerability #1 is the highest priority for every type of institution
- B. Vulnerability #1 and vulnerability #2 have the same priority
- C. The highest priority for handling depends on the type of institution deploying the devices
- D. Vulnerability #2 is the highest priority for every type of institution
Answer: A
NEW QUESTION 47
A SOC analyst detected a ransomware outbreak in the organization coming from a malicious email attachment. Affected parties are notified, and the incident response team is assigned to the case. According to the NIST incident response handbook, what is the next step in handling the incident?
- A. Eradicate malicious software from the infected machines.
- B. Perform a vulnerability assessment to find existing vulnerabilities.
- C. Create a follow-up report based on the incident documentation.
- D. Collect evidence and maintain a chain-of-custody during further analysis.
Answer: D
NEW QUESTION 48
An organization lost connectivity to critical servers, and users cannot access business applications and internal websites. An engineer checks the network devices to investigate the outage and determines that all devices are functioning. Drag and drop the steps from the left into the sequence on the right to continue investigating this issue. Not all options are used.
Answer:
Explanation:
NEW QUESTION 49
An organization had several cyberattacks over the last 6 months and has tasked an engineer with looking for patterns or trends that will help the organization anticipate future attacks and mitigate them. Which data analytic technique should the engineer use to accomplish this task?
- A. diagnostic
- B. predictive
- C. qualitative
- D. statistical
Answer: B
NEW QUESTION 50
Refer to the exhibit.
Which indicator of compromise is represented by this STIX?
- A. website redirecting traffic to ransomware server
- B. website hosting malware to download files
- C. web server vulnerability exploited by malware
- D. cross-site scripting vulnerability to backdoor server
Answer: C
NEW QUESTION 51
A company recently started accepting credit card payments in their local warehouses and is undergoing a PCI audit. Based on business requirements, the company needs to store sensitive authentication data for 45 days. How must data be stored for compliance?
- A. by entities that issue the payment cards or that perform support issuing services
- B. by issuers and issuer processors if there is a legitimate reason
- C. post-authorization by non-issuing entities if the data is encrypted and securely stored
- D. post-authorization by non-issuing entities if there is a documented business justification
Answer: C
NEW QUESTION 52
......
Understanding helpful and specific pieces of 350-201 CISCO Performing CyberOps Using Cisco Security
The going with will be inspected in CISCO 350-201 exam dumps:
- Apply the standards of DevOps rehearses
- Interpret essential contents (for instance, Python)
- Modify a gave content to computerize a security activities task
- Determine openings for mechanization and arrangement
- Explain the basic HTTP reaction codes related with REST APIs
- Evaluate the pieces of a HTTP (reaction code, headers, body)
100% Real & Accurate 350-201 Questions and Answers with Free and Fast Updates: https://www.latestcram.com/350-201-exam-cram-questions.html
Get Unlimited Access to 350-201 Certification Exam Cert Guide: https://drive.google.com/open?id=1HABQWgWlSOmR5UgQkV_DbUkX_nn9uLK6
