Feb-2022 Cisco 350-201 Actual Questions and 100% Cover Real Exam Questions [Q12-Q31]

Share

Feb-2022 Cisco 350-201 Actual Questions and 100% Cover Real Exam Questions

350-201 Free Exam Questions and Answers PDF Updated on Feb-2022

NEW QUESTION 12

Refer to the exhibit. An engineer is analyzing this Vlan0392-int12-239.pcap file in Wireshark after detecting a suspicious network activity. The origin header for the direct IP connections in the packets was initiated by a google chrome extension on a WebSocket protocol. The engineer checked message payloads to determine what information was being sent off-site but the payloads are obfuscated and unreadable. What does this STIX indicate?

  • A. The extension is not performing as intended because of restrictions since ports 80 and 443 should be accessible
  • B. The traffic is legitimate as the google chrome extension is reaching out to check for updates and fetches this information
  • C. There is a malware that is communicating via encrypted channels to the command and control server
  • D. There is a possible data leak because payloads should be encoded as UTF-8 text

Answer: D

 

NEW QUESTION 13
Refer to the exhibit.

Where are the browser page rendering permissions displayed?

  • A. x-test-debug
  • B. x-content-type-options
  • C. x-xss-protection
  • D. x-frame-options

Answer: B

 

NEW QUESTION 14
An engineer implemented a SOAR workflow to detect and respond to incorrect login attempts and anomalous user behavior. Since the implementation, the security team has received dozens of false positive alerts and negative feedback from system administrators and privileged users. Several legitimate users were tagged as a threat and their accounts blocked, or credentials reset because of unexpected login times and incorrectly typed credentials. How should the workflow be improved to resolve these issues?

  • A. Increase incorrect login tries and tune anomalous user behavior not to affect privileged accounts
  • B. Add a confirmation step through which SOAR informs the affected user and asks them to confirm whether they made the attempts
  • C. Meet with privileged users to increase awareness and modify the rules for threat tags and anomalous behavior alerts
  • D. Change the SOAR configuration flow to remove the automatic remediation that is increasing the false positives and triggering threats

Answer: D

 

NEW QUESTION 15
An analyst wants to upload an infected file containing sensitive information to a hybrid-analysis sandbox. According to the NIST.SP 800-150 guide to cyber threat information sharing, what is the analyst required to do before uploading the file to safeguard privacy?

  • A. Lock the file to prevent unauthorized access.
  • B. Ensure the online sandbox is GDPR compliant.
  • C. Remove all personally identifiable information.
  • D. Verify hash integrity.

Answer: C

 

NEW QUESTION 16
What is idempotence?

  • A. the assurance of system uniformity throughout the whole delivery process
  • B. the ability to recover from failures while keeping critical services running
  • C. the ability to set the target environment configuration regardless of the starting state
  • D. the necessity of setting maintenance of individual deployment environments

Answer: A

 

NEW QUESTION 17
Drag and drop the threat from the left onto the scenario that introduces the threat on the right. Not all options are used.

Answer:

Explanation:

 

NEW QUESTION 18
A SOC team is investigating a recent, targeted social engineering attack on multiple employees. Cross- correlated log analysis revealed that two hours before the attack, multiple assets received requests on TCP port 79. Which action should be taken by the SOC team to mitigate this attack?

  • A. Configure affected devices to disable NETRJS protocol.
  • B. Configure affected devices to disable the Finger service.
  • C. Disable BIND forwarding from the DNS server to avoid reconnaissance.
  • D. Disable affected assets and isolate them for further investigation.

Answer: B

 

NEW QUESTION 19
A security expert is investigating a breach that resulted in a $32 million loss from customer accounts. Hackers were able to steal API keys and two-factor codes due to a vulnerability that was introduced in a new code a few weeks before the attack. Which step was missed that would have prevented this breach?

  • A. use of SecDevOps to detect the vulnerability during development
  • B. implementation of an endpoint protection system
  • C. implementation of a firewall and intrusion detection system
  • D. use of the Nmap tool to identify the vulnerability when the new code was deployed

Answer: A

 

NEW QUESTION 20
Refer to the exhibit.

An engineer is performing a static analysis on a malware and knows that it is capturing keys and webcam events on a company server. What is the indicator of compromise?

  • A. The malware has moved to harvesting cookies and stored account information from major browsers and configuring a reverse proxy for intercepting network activity.
  • B. The malware contains an encryption and decryption routine to hide URLs/IP addresses and is storing the output of loggers and webcam captures in locally encrypted files for retrieval.
  • C. The malware is performing comprehensive fingerprinting of the host, including a processor, motherboard manufacturer, and connected removable storage.
  • D. The malware is a ransomware querying for installed anti-virus products and operating systems to encrypt and render unreadable until payment is made for file decryption.

Answer: D

 

NEW QUESTION 21

Refer to the exhibit. An engineer is investigating a case with suspicious usernames within the active directory.
After the engineer investigates and cross-correlates events from other sources, it appears that the 2 users are privileged, and their creation date matches suspicious network traffic that was initiated from the internal network 2 days prior. Which type of compromise is occurring?

  • A. compromised network
  • B. compromised database tables
  • C. compromised insider
  • D. compromised root access

Answer: A

 

NEW QUESTION 22

Refer to the exhibit. Where does it signify that a page will be stopped from loading when a scripting attack is detected?

  • A. x-xss-protection
  • B. x-test-debug
  • C. x-frame-options
  • D. x-content-type-options

Answer: A

Explanation:
Explanation/Reference: https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/operations/customize-http-security- headers-ad-fs

 

NEW QUESTION 23
Refer to the exhibit.

An engineer configured this SOAR solution workflow to identify account theft threats and privilege escalation, evaluate risk, and respond by resolving the threat. This solution is handling more threats than Security analysts have time to analyze. Without this analysis, the team cannot be proactive and anticipate attacks. Which action will accomplish this goal?

  • A. Include a step "Reporting" to alert the security department of threats identified by the SOAR reporting engine
  • B. Exclude the step "BAN malicious IP" to allow analysts to conduct and track the remediation
  • C. Include a step "Take a Snapshot" to capture the endpoint state to contain the threat for analysis
  • D. Exclude the step "Check for GeoIP location" to allow analysts to analyze the location and the associated risk based on asset criticality

Answer: B

 

NEW QUESTION 24
Drag and drop the actions below the image onto the boxes in the image for the actions that should be taken during this playbook step. Not all options are used.

Answer:

Explanation:

 

NEW QUESTION 25
An organization suffered a security breach in which the attacker exploited a Netlogon Remote Protocol vulnerability for further privilege escalation. Which two actions should the incident response team take to prevent this type of attack from reoccurring? (Choose two.)

  • A. Define roles and responsibilities in the incident response playbook.
  • B. Apply existing patches to the company servers.
  • C. Scan the company server files for known viruses.
  • D. Implement a patch management process.
  • E. Automate antivirus scans of the company servers.

Answer: A,E

 

NEW QUESTION 26
A logistic company must use an outdated application located in a private VLAN during the migration to new technologies. The IPS blocked and reported an unencrypted communication. Which tuning option should be applied to IPS?

  • A. Allow list only authorized hosts to contact the application's IP at a specific port.
  • B. Allow list only authorized hosts to contact the application's VLAN.
  • C. Allow list traffic to application's IP from the internal network at a specific port.
  • D. Allow list HTTP traffic through the corporate VLANS.

Answer: B

 

NEW QUESTION 27
What is a principle of Infrastructure as Code?

  • A. System downtime is grouped and scheduled across the infrastructure
  • B. Scripts and manual configurations work together to ensure repeatable routines
  • C. System maintenance is delegated to software systems
  • D. Comprehensive initial designs support robust systems

Answer: D

 

NEW QUESTION 28
Refer to the exhibit.

How are tokens authenticated when the REST API on a device is accessed from a REST API client?

  • A. The token is obtained by providing a password. The REST API requests access to a resource using the access token, validates the access token, and gives access to the resource.
  • B. The token is obtained before providing a password. The REST client provides access to a resource using the access token. The REST API encrypts the access token and gives access to the resource.
  • C. The token is obtained by providing a password. The REST client requests access to a resource using the access token. The REST API validates the access token and gives access to the resource.
  • D. The token is obtained before providing a password. The REST API provides resource access, refreshes tokens, and returns them to the REST client. The REST client requests access to a resource using the access token.

Answer: B

 

NEW QUESTION 29
An engineer is moving data from NAS servers in different departments to a combined storage database so that the data can be accessed and analyzed by the organization on-demand. Which data management process is being used?

  • A. data ingestion
  • B. data regression
  • C. data clustering
  • D. data obfuscation

Answer: C

 

NEW QUESTION 30
Refer to the exhibit.

Where are the browser page rendering permissions displayed?

  • A. X-Frame-Options
  • B. Content-Type
  • C. Cache-Control
  • D. X-XSS-Protection

Answer: B

 

NEW QUESTION 31
......


Cisco 350-201 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Describe use and concepts of tools for security data analytics
  • Describe the concepts of security data management
Topic 2
  • Infer the industry for various compliance standards
  • Evaluate the parts of an HTTP response
Topic 3
  • Modify a provided script to automate a security operations task
  • Determine opportunities for automation and orchestration
Topic 4
  • Describe the different mechanisms to detect and enforce data loss prevention techniques
  • Evaluate artifacts and streams in a packet capture file
Topic 5
  • Determine the next action based on user behavior alerts
  • Determine the steps to investigate the common types of cases
Topic 6
  • Apply the playbook for a common scenario
  • Describe characteristics and areas of improvement using common incident response metrics
Topic 7
  • Interpret the sequence of events during an attack based on analysis of traffic patterns
  • Interpret the components within a playbook
Topic 8
  • Compare security operations considerations of cloud platforms
  • Determine the tools needed based on a playbook scenario
Topic 9
  • Describe the process of evaluating the security posture of an asset
  • Determine patching recommendations, given a scenario
Topic 10
  • Describe the concepts and limitations of cyber risk insurance
  • Describe the use of hardening machine images for deployment

 

Cisco 350-201 Real 2022 Braindumps Mock Exam Dumps: https://www.bootcamppdf.com/350-201_exam-dumps.html

Latest 350-201 Exam Dumps Recently Updated 141 Questions: https://drive.google.com/open?id=1yxPafR0JdJ0dxkYnCf8nQ0wxNNmMaTNZ