Feb-2022 Cisco 350-201 Actual Questions and 100% Cover Real Exam Questions
350-201 Free Exam Questions and Answers PDF Updated on Feb-2022
NEW QUESTION 12 
Refer to the exhibit. An engineer is analyzing this Vlan0392-int12-239.pcap file in Wireshark after detecting a suspicious network activity. The origin header for the direct IP connections in the packets was initiated by a google chrome extension on a WebSocket protocol. The engineer checked message payloads to determine what information was being sent off-site but the payloads are obfuscated and unreadable. What does this STIX indicate?
- A. The extension is not performing as intended because of restrictions since ports 80 and 443 should be accessible
- B. The traffic is legitimate as the google chrome extension is reaching out to check for updates and fetches this information
- C. There is a malware that is communicating via encrypted channels to the command and control server
- D. There is a possible data leak because payloads should be encoded as UTF-8 text
Answer: D
NEW QUESTION 13
Refer to the exhibit.
Where are the browser page rendering permissions displayed?
- A. x-test-debug
- B. x-content-type-options
- C. x-xss-protection
- D. x-frame-options
Answer: B
NEW QUESTION 14
An engineer implemented a SOAR workflow to detect and respond to incorrect login attempts and anomalous user behavior. Since the implementation, the security team has received dozens of false positive alerts and negative feedback from system administrators and privileged users. Several legitimate users were tagged as a threat and their accounts blocked, or credentials reset because of unexpected login times and incorrectly typed credentials. How should the workflow be improved to resolve these issues?
- A. Increase incorrect login tries and tune anomalous user behavior not to affect privileged accounts
- B. Add a confirmation step through which SOAR informs the affected user and asks them to confirm whether they made the attempts
- C. Meet with privileged users to increase awareness and modify the rules for threat tags and anomalous behavior alerts
- D. Change the SOAR configuration flow to remove the automatic remediation that is increasing the false positives and triggering threats
Answer: D
NEW QUESTION 15
An analyst wants to upload an infected file containing sensitive information to a hybrid-analysis sandbox. According to the NIST.SP 800-150 guide to cyber threat information sharing, what is the analyst required to do before uploading the file to safeguard privacy?
- A. Lock the file to prevent unauthorized access.
- B. Ensure the online sandbox is GDPR compliant.
- C. Remove all personally identifiable information.
- D. Verify hash integrity.
Answer: C
NEW QUESTION 16
What is idempotence?
- A. the assurance of system uniformity throughout the whole delivery process
- B. the ability to recover from failures while keeping critical services running
- C. the ability to set the target environment configuration regardless of the starting state
- D. the necessity of setting maintenance of individual deployment environments
Answer: A
NEW QUESTION 17
Drag and drop the threat from the left onto the scenario that introduces the threat on the right. Not all options are used.
Answer:
Explanation:
NEW QUESTION 18
A SOC team is investigating a recent, targeted social engineering attack on multiple employees. Cross- correlated log analysis revealed that two hours before the attack, multiple assets received requests on TCP port 79. Which action should be taken by the SOC team to mitigate this attack?
- A. Configure affected devices to disable NETRJS protocol.
- B. Configure affected devices to disable the Finger service.
- C. Disable BIND forwarding from the DNS server to avoid reconnaissance.
- D. Disable affected assets and isolate them for further investigation.
Answer: B
NEW QUESTION 19
A security expert is investigating a breach that resulted in a $32 million loss from customer accounts. Hackers were able to steal API keys and two-factor codes due to a vulnerability that was introduced in a new code a few weeks before the attack. Which step was missed that would have prevented this breach?
- A. use of SecDevOps to detect the vulnerability during development
- B. implementation of an endpoint protection system
- C. implementation of a firewall and intrusion detection system
- D. use of the Nmap tool to identify the vulnerability when the new code was deployed
Answer: A
NEW QUESTION 20
Refer to the exhibit.
An engineer is performing a static analysis on a malware and knows that it is capturing keys and webcam events on a company server. What is the indicator of compromise?
- A. The malware has moved to harvesting cookies and stored account information from major browsers and configuring a reverse proxy for intercepting network activity.
- B. The malware contains an encryption and decryption routine to hide URLs/IP addresses and is storing the output of loggers and webcam captures in locally encrypted files for retrieval.
- C. The malware is performing comprehensive fingerprinting of the host, including a processor, motherboard manufacturer, and connected removable storage.
- D. The malware is a ransomware querying for installed anti-virus products and operating systems to encrypt and render unreadable until payment is made for file decryption.
Answer: D
NEW QUESTION 21 
Refer to the exhibit. An engineer is investigating a case with suspicious usernames within the active directory.
After the engineer investigates and cross-correlates events from other sources, it appears that the 2 users are privileged, and their creation date matches suspicious network traffic that was initiated from the internal network 2 days prior. Which type of compromise is occurring?
- A. compromised network
- B. compromised database tables
- C. compromised insider
- D. compromised root access
Answer: A
NEW QUESTION 22 
Refer to the exhibit. Where does it signify that a page will be stopped from loading when a scripting attack is detected?
- A. x-xss-protection
- B. x-test-debug
- C. x-frame-options
- D. x-content-type-options
Answer: A
Explanation:
Explanation/Reference: https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/operations/customize-http-security- headers-ad-fs
NEW QUESTION 23
Refer to the exhibit.
An engineer configured this SOAR solution workflow to identify account theft threats and privilege escalation, evaluate risk, and respond by resolving the threat. This solution is handling more threats than Security analysts have time to analyze. Without this analysis, the team cannot be proactive and anticipate attacks. Which action will accomplish this goal?
- A. Include a step "Reporting" to alert the security department of threats identified by the SOAR reporting engine
- B. Exclude the step "BAN malicious IP" to allow analysts to conduct and track the remediation
- C. Include a step "Take a Snapshot" to capture the endpoint state to contain the threat for analysis
- D. Exclude the step "Check for GeoIP location" to allow analysts to analyze the location and the associated risk based on asset criticality
Answer: B
NEW QUESTION 24
Drag and drop the actions below the image onto the boxes in the image for the actions that should be taken during this playbook step. Not all options are used.
Answer:
Explanation:
NEW QUESTION 25
An organization suffered a security breach in which the attacker exploited a Netlogon Remote Protocol vulnerability for further privilege escalation. Which two actions should the incident response team take to prevent this type of attack from reoccurring? (Choose two.)
- A. Define roles and responsibilities in the incident response playbook.
- B. Apply existing patches to the company servers.
- C. Scan the company server files for known viruses.
- D. Implement a patch management process.
- E. Automate antivirus scans of the company servers.
Answer: A,E
NEW QUESTION 26
A logistic company must use an outdated application located in a private VLAN during the migration to new technologies. The IPS blocked and reported an unencrypted communication. Which tuning option should be applied to IPS?
- A. Allow list only authorized hosts to contact the application's IP at a specific port.
- B. Allow list only authorized hosts to contact the application's VLAN.
- C. Allow list traffic to application's IP from the internal network at a specific port.
- D. Allow list HTTP traffic through the corporate VLANS.
Answer: B
NEW QUESTION 27
What is a principle of Infrastructure as Code?
- A. System downtime is grouped and scheduled across the infrastructure
- B. Scripts and manual configurations work together to ensure repeatable routines
- C. System maintenance is delegated to software systems
- D. Comprehensive initial designs support robust systems
Answer: D
NEW QUESTION 28
Refer to the exhibit.
How are tokens authenticated when the REST API on a device is accessed from a REST API client?
- A. The token is obtained by providing a password. The REST API requests access to a resource using the access token, validates the access token, and gives access to the resource.
- B. The token is obtained before providing a password. The REST client provides access to a resource using the access token. The REST API encrypts the access token and gives access to the resource.
- C. The token is obtained by providing a password. The REST client requests access to a resource using the access token. The REST API validates the access token and gives access to the resource.
- D. The token is obtained before providing a password. The REST API provides resource access, refreshes tokens, and returns them to the REST client. The REST client requests access to a resource using the access token.
Answer: B
NEW QUESTION 29
An engineer is moving data from NAS servers in different departments to a combined storage database so that the data can be accessed and analyzed by the organization on-demand. Which data management process is being used?
- A. data ingestion
- B. data regression
- C. data clustering
- D. data obfuscation
Answer: C
NEW QUESTION 30
Refer to the exhibit.
Where are the browser page rendering permissions displayed?
- A. X-Frame-Options
- B. Content-Type
- C. Cache-Control
- D. X-XSS-Protection
Answer: B
NEW QUESTION 31
......
Cisco 350-201 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
| Topic 8 |
|
| Topic 9 |
|
| Topic 10 |
|
Cisco 350-201 Real 2022 Braindumps Mock Exam Dumps: https://www.bootcamppdf.com/350-201_exam-dumps.html
Latest 350-201 Exam Dumps Recently Updated 141 Questions: https://drive.google.com/open?id=1yxPafR0JdJ0dxkYnCf8nQ0wxNNmMaTNZ