Cisco 350-201 Real Exam Questions and Answers FREE [Q67-Q84]

Share

Cisco 350-201 Real Exam Questions and Answers FREE

Exam Dumps 350-201 Practice Free Latest Cisco Practice Tests

NEW QUESTION # 67

Refer to the exhibit. An engineer is reverse engineering a suspicious file by examining its resources. What does this file indicate?

  • A. an archived malware
  • B. a DOS MZ executable format
  • C. a MS-DOS executable archive
  • D. a Windows executable file

Answer: D

Explanation:
Explanation/Reference: https://stackoverflow.com/questions/2577545/why-is-this-program-cannot-be-run-in-dos-mode-text- present-in-dll-files#:~:text=The%20linker%20places%20a%20default,using%20the%20%2FSTUB%20linker%
20option.&text=This%20information%20enables%20Windows%20to,has%20an%20MS-DOS%20stub.


NEW QUESTION # 68
Engineers are working to document, list, and discover all used applications within an organization. During the regular assessment of applications from the HR backup server, an engineer discovered an unknown application. The analysis showed that the application is communicating with external addresses on a non- secure, unencrypted channel. Information gathering revealed that the unknown application does not have an owner and is not being used by a business unit. What are the next two steps the engineers should take in this investigation? (Choose two.)

  • A. Initiate a triage meeting with department leads to determine if the application is owned internally or used by any business unit and document the asset owner.
  • B. Determine the type of data stored on the affected asset, document the access logs, and engage the incident response team.
  • C. Identify who installed the application by reviewing the logs and gather a user access log from the HR department.
  • D. Verify user credentials on the affected asset, modify passwords, and confirm available patches and updates are installed.

Answer: A,B


NEW QUESTION # 69
A new malware variant is discovered hidden in pirated software that is distributed on the Internet. Executives have asked for an organizational risk assessment. The security officer is given a list of all assets. According to NIST, which two elements are missing to calculate the risk assessment? (Choose two.)

  • A. malware analysis report
  • B. asset vulnerability assessment
  • C. key assets and executives
  • D. report of staff members with asset relations
  • E. incident response playbooks

Answer: A,B


NEW QUESTION # 70
Drag and drop the actions below the image onto the boxes in the image for the actions that should be taken during this playbook step. Not all options are used.

Answer:

Explanation:


NEW QUESTION # 71
Refer to the exhibit. Which asset has the highest risk value?

  • A. website
  • B. secretary workstation
  • C. servers
  • D. payment process

Answer: D


NEW QUESTION # 72
Refer to the exhibit.

Which data format is being used?

  • A. JSON
  • B. XML
  • C. CSV
  • D. HTML

Answer: D


NEW QUESTION # 73
An engineer received an alert of a zero-day vulnerability affecting desktop phones through which an attacker sends a crafted packet to a device, resets the credentials, makes the device unavailable, and allows a default administrator account login. Which step should an engineer take after receiving this alert?

  • A. Determine company usage of the affected products
  • B. Search for a patch to install from the vendor
  • C. Initiate a triage meeting to acknowledge the vulnerability and its potential impact
  • D. Implement restrictions within the VoIP VLANS

Answer: B


NEW QUESTION # 74
Refer to the exhibit. What is the connection status of the ICMP event?

  • A. allowed in the default action
  • B. blocked by an intrusion policy rule
  • C. allowed by a configured access policy rule
  • D. blocked by a configured access policy rule

Answer: C

Explanation:
Explanation/Reference:


NEW QUESTION # 75
What is a limitation of cyber security risk insurance?

  • A. It does not cover the costs to restore stolen identities as a result of a cyber attack
  • B. It does not cover the costs to hire forensics experts to analyze the cyber attack
  • C. It does not cover the costs to hire a public relations company to help deal with a cyber attack
  • D. It does not cover the costs of damage done by third parties as a result of a cyber attack

Answer: A


NEW QUESTION # 76
Refer to the exhibit.

An engineer notices a significant anomaly in the traffic in one of the host groups in Cisco Secure Network Analytics (Stealthwatch) and must analyze the top data transmissions. Which tool accomplishes this task?

  • A. Top Ports
  • B. Top Conversations
  • C. Top Peers
  • D. Top Hosts

Answer: D


NEW QUESTION # 77
A security manager received an email from an anomaly detection service, that one of their contractors has downloaded 50 documents from the company's confidential document management folder using a company- owned asset al039-ice-4ce687TL0500. A security manager reviewed the content of downloaded documents and noticed that the data affected is from different departments. What are the actions a security manager should take?

  • A. Communicate with the contractor to identify the motives.
  • B. Escalate to contractor's manager.
  • C. Report to the incident response team.
  • D. Measure confidentiality level of downloaded documents.

Answer: C


NEW QUESTION # 78
Drag and drop the phases to evaluate the security posture of an asset from the left onto the activity that happens during the phases on the right.

Answer:

Explanation:


NEW QUESTION # 79
What do 2xx HTTP response codes indicate for REST APIs?

  • A. the server takes responsibility for error status codes
  • B. successful acceptance of the client's request
  • C. additional action must be taken by the client to complete the request
  • D. communication of transfer protocol-level information

Answer: B


NEW QUESTION # 80
Refer to the exhibit.

An employee is a victim of a social engineering phone call and installs remote access software to allow an "MS Support" technician to check his machine for malware. The employee becomes suspicious after the remote technician requests payment in the form of gift cards. The employee has copies of multiple, unencrypted database files, over 400 MB each, on his system and is worried that the scammer copied the files off but has no proof of it. The remote technician was connected sometime between 2:00 pm and 3:00 pm over https. What should be determined regarding data loss between the employee's laptop and the remote technician's system?

  • A. The database files were intentionally corrupted, and encryption is possible
  • B. The database files integrity was violated
  • C. The database files were disclosed
  • D. No database files were disclosed

Answer: B


NEW QUESTION # 81
Refer to the exhibit.

A threat actor behind a single computer exploited a cloud-based application by sending multiple concurrent API requests. These requests made the application unresponsive. Which solution protects the application from being overloaded and ensures more equitable application access across the end-user community?

  • A. Reduce the amount of data that can be fetched from the total pool of active clients that call the API
  • B. Add restrictions on the edge router on how often a single client can access the API
  • C. Increase the application cache of the total pool of active clients that call the API
  • D. Limit the number of API calls that a single client is allowed to make

Answer: D


NEW QUESTION # 82
Drag and drop the NIST incident response process steps from the left onto the actions that occur in the steps on the right.

Answer:

Explanation:

Reference:
https://www.securitymetrics.com/blog/6-phases-incident-response-plan


NEW QUESTION # 83
After a recent malware incident, the forensic investigator is gathering details to identify the breach and causes. The investigator has isolated the affected workstation. What is the next step that should be taken in this investigation?

  • A. Compare workstation configuration and asset configuration policy to identify gaps.
  • B. Review audit logs for privilege escalation events.
  • C. Inspect registry entries for recently executed files.
  • D. Analyze the applications and services running on the affected workstation.

Answer: C


NEW QUESTION # 84
......

Verified 350-201 Exam Dumps Q&As - Provide 350-201 with Correct Answers: https://braindumps.exam4tests.com/350-201-pdf-braindumps.html