Spring Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

200-201 Exam Dumps - Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS)

Searching for workable clues to ace the Cisco 200-201 Exam? You’re on the right place! ExamCert has realistic, trusted and authentic exam prep tools to help you achieve your desired credential. ExamCert’s 200-201 PDF Study Guide, Testing Engine and Exam Dumps follow a reliable exam preparation strategy, providing you the most relevant and updated study material that is crafted in an easy to learn format of questions and answers. ExamCert’s study tools aim at simplifying all complex and confusing concepts of the exam and introduce you to the real exam scenario and practice it with the help of its testing engine and real exam dumps

Go to page:
Question # 49

Refer to the exhibit. Based on the .pcap file, which protocol's vulnerability has been exploited to establish a session?

A.

SMB

B.

TCP

C.

Negotiate

D.

IP

Full Access
Question # 50

Refer to the exhibit.

In which Linux log file is this output found?

A.

/var/log/authorization.log

B.

/var/log/dmesg

C.

var/log/var.log

D.

/var/log/auth.log

Full Access
Question # 51

Which data format is the most efficient to build a baseline of traffic seen over an extended period of time?

A.

syslog messages

B.

full packet capture

C.

NetFlow

D.

firewall event logs

Full Access
Question # 52

Which evasion technique is a function of ransomware?

A.

extended sleep calls

B.

encryption

C.

resource exhaustion

D.

encoding

Full Access
Question # 53

A software development company develops high-end technology for the customer that will go through the HIPAA audit program. The technology will be hosted in the cloud, and the healthcare, employee names, and contact information will be stored on two separate logically isolated private cloud services. The patents and inventions will be hosted on a separate encrypted database. A compliance team is asked to analyze the cloud infrastructure and architecture to identify the protected data. Which two types of protected data should be identified? (Choose two.)

A.

Federated Identity ID (FII)

B.

Protected Health Information (PHI)

C.

Personally Identifiable Information (PII)

D.

Payment Card Industry (PCI)

E.

Self-sovereign Identity (SSI)

Full Access
Question # 54

What are the two differences between vulnerability and exploit? (Choose two.)

A.

Known vulnerabilities are assigned special CVE numbers, and exploits are using process to take advantage of vulnerabilities.

B.

Vulnerabilities can be found in hardware and software, and exploits can be used only for software-based vulnerabilities.

C.

Zero-day exploit can be used to take advantage of a vulnerability until the vulnerable software or hardware is patched.

D.

Vulnerabilities are usually populated in the dark web, and exploit tools and methods can be found in the public web.

E.

Zero-day exploit can be used for taking advantage of a known vulnerability, and cyber-attack can be performed on company assets.

Full Access
Question # 55

What describes the impact of false-positive alerts compared to false-negative alerts?

A.

A false negative is alerting for an XSS attack. An engineer investigates the alert and discovers that an XSS attack happened A false positive is when an XSS attack happens and no alert is raised

B.

A false negative is a legitimate attack triggering a brute-force alert. An engineer investigates the alert and finds out someone intended to break into the system A false positive is when no alert and no attack is occurring

C.

A false positive is an event alerting for a brute-force attack An engineer investigates the alert and discovers that a legitimate user entered the wrong credential several times A false negative is when a threat actor tries to brute-force attack a system and no alert is raised.

D.

A false positive is an event alerting for an SQL injection attack An engineer investigates the alert and discovers that an attack attempt was blocked by IPS A false negative is when the attack gets detected but succeeds and results in a breach.

Full Access
Question # 56

A security engineer must protect the company from known issues that trigger adware. Recently new incident has been raised that could harm the system. Which security concepts are present in this scenario?

A.

exploit and patching

B.

risk and evidence

C.

analysis and remediation

D.

vulnerability and threat

Full Access
Go to page: