Pass 350-201 Exam in First Attempt Guaranteed 2021 Dumps!
350-201 Dumps Full Questions - Exam Study Guide
NEW QUESTION 83
Refer to the exhibit. What is the connection status of the ICMP event?
- A. allowed in the default action
- B. allowed by a configured access policy rule
- C. blocked by a configured access policy rule
- D. blocked by an intrusion policy rule
Answer: B
Explanation:
Explanation/Reference:
NEW QUESTION 84
Refer to the exhibit.
An engineer is investigating a case with suspicious usernames within the active directory. After the engineer investigates and cross-correlates events from other sources, it appears that the 2 users are privileged, and their creation date matches suspicious network traffic that was initiated from the internal network 2 days prior. Which type of compromise is occurring?
- A. compromised database tables
- B. compromised network
- C. compromised root access
- D. compromised insider
Answer: B
NEW QUESTION 85
Refer to the exhibit.
What is occurring in this packet capture?
- A. DNS tunneling
- B. TCP flood
- C. TCP port scan
- D. DNS flood
Answer: B
NEW QUESTION 86
An organization suffered a security breach in which the attacker exploited a Netlogon Remote Protocol vulnerability for further privilege escalation. Which two actions should the incident response team take to prevent this type of attack from reoccurring? (Choose two.)
- A. Define roles and responsibilities in the incident response playbook.
- B. Apply existing patches to the company servers.
- C. Automate antivirus scans of the company servers.
- D. Scan the company server files for known viruses.
- E. Implement a patch management process.
Answer: A,C
NEW QUESTION 87
An engineer detects an intrusion event inside an organization's network and becomes aware that files that contain personal data have been accessed. Which action must be taken to contain this attack?
- A. Analyze the source.
- B. Access the affected server to confirm compromised files are encrypted.
- C. Disconnect the affected server from the network.
- D. Determine the attack surface.
Answer: B
NEW QUESTION 88
An engineer is analyzing a possible compromise that happened a week ago when the company database servers unexpectedly went down. The analysis reveals that attackers tampered with Microsoft SQL Server Resolution Protocol and launched a DDoS attack. The engineer must act quickly to ensure that all systems are protected. Which two tools should be used to detect and mitigate this type of future attack? (Choose two.)
- A. autopsy
- B. IPS
- C. Wireshark
- D. SHA512
- E. firewall
Answer: C,E
NEW QUESTION 89
How does Wireshark decrypt TLS network traffic?
- A. using an RSA public key
- B. by defining a user-specified decode-as
- C. by observing DH key exchange
- D. with a key log file using per-session secrets
Answer: D
Explanation:
Explanation/Reference: https://wiki.wireshark.org/TLS
NEW QUESTION 90
Drag and drop the components from the left onto the phases of the CI/CD pipeline on the right.
Answer:
Explanation:
Reference:
https://www.densify.com/resources/continuous-integration-delivery-phases
NEW QUESTION 91
Refer to the exhibit.
IDS is producing an increased amount of false positive events about brute force attempts on the organization's mail server. How should the Snort rule be modified to improve performance?
- A. Tune the count and seconds threshold of the rule
- B. Set the rule to track the source IP
- C. Block list of internal IPs from the rule
- D. Change the rule content match to case sensitive
Answer: D
NEW QUESTION 92 
Refer to the exhibit. Cisco Rapid Threat Containment using Cisco Secure Network Analytics (Stealthwatch) and ISE detects the threat of malware-infected 802.1x authenticated endpoints and places that endpoint into a Quarantine VLAN using Adaptive Network Control policy. Which telemetry feeds were correlated with SMC to identify the malware?
- A. SNMP and syslog data
- B. NetFlow and event data
- C. event data and syslog data
- D. NetFlow and SNMP
Answer: C
NEW QUESTION 93
An engineer notices that every Sunday night, there is a two-hour period with a large load of network activity. Upon further investigation, the engineer finds that the activity is from locations around the globe outside the organization's service are a. What are the next steps the engineer must take?
- A. Review the SIEM and FirePower logs, block all traffic, and document the results of calling the call center.
- B. Assign the issue to the incident handling provider because no suspicious activity has been observed during business hours.
- C. Define the access points using StealthWatch or SIEM logs, understand services being offered during the hours in Question:, and cross-correlate other source events.
- D. Treat it as a false positive, and accept the SIEM issue as valid to avoid alerts from triggering on weekends.
Answer: B
NEW QUESTION 94
An engineer receives an incident ticket with hundreds of intrusion alerts that require investigation. An analysis of the incident log shows that the alerts are from trusted IP addresses and internal devices. The final incident report stated that these alerts were false positives and that no intrusions were detected. What action should be taken to harden the network?
- A. Configure reverse port forwarding on the IPS
- B. Move the IPS to after the firewall facing the internal network
- C. Move the IPS to before the firewall facing the outside network
- D. Configure the proxy service on the IPS
Answer: D
NEW QUESTION 95
How is a SIEM tool used?
- A. To collect security data from authentication failures and cyber attacks and forward it for analysis
- B. To collect and analyze security data from network devices and servers and produce alerts
- C. To search and compare security data against acceptance standards and generate reports for analysis
- D. To compare security alerts against configured scenarios and trigger system responses
Answer: B
Explanation:
Explanation/Reference: https://www.varonis.com/blog/what-is-siem/
NEW QUESTION 96
What is the difference between process orchestration and automation?
- A. Orchestration minimizes redundancies, while automation decreases the time to recover from redundancies.
- B. Orchestration arranges the tasks, while automation arranges processes.
- C. Automation optimizes the individual tasks to execute the process, while orchestration optimizes frequent and repeatable processes.
- D. Orchestration combines a set of automated tools, while automation is focused on the tools to automate process flows.
Answer: D
NEW QUESTION 97
Where do threat intelligence tools search for data to identify potential malicious IP addresses, domain names, and URLs?
- A. Internet
- B. internal cloud
- C. internal database
- D. customer data
Answer: A
NEW QUESTION 98
A threat actor used a phishing email to deliver a file with an embedded macro. The file was opened, and a remote code execution attack occurred in a company's infrastructure. Which steps should an engineer take at the recovery stage?
- A. Identify the attack vector and update the IDS signature list
- B. Determine the systems involved and deploy available patches
- C. Review access lists and require users to increase password complexity
- D. Analyze event logs and restrict network access
Answer: D
NEW QUESTION 99
A SOC team is investigating a recent, targeted social engineering attack on multiple employees. Cross- correlated log analysis revealed that two hours before the attack, multiple assets received requests on TCP port 79. Which action should be taken by the SOC team to mitigate this attack?
- A. Configure affected devices to disable the Finger service.
- B. Configure affected devices to disable NETRJS protocol.
- C. Disable affected assets and isolate them for further investigation.
- D. Disable BIND forwarding from the DNS server to avoid reconnaissance.
Answer: A
NEW QUESTION 100
Refer to the exhibit.
An engineer configured this SOAR solution workflow to identify account theft threats and privilege escalation, evaluate risk, and respond by resolving the threat. This solution is handling more threats than Security analysts have time to analyze. Without this analysis, the team cannot be proactive and anticipate attacks. Which action will accomplish this goal?
- A. Exclude the step "Check for GeoIP location" to allow analysts to analyze the location and the associated risk based on asset criticality
- B. Include a step "Reporting" to alert the security department of threats identified by the SOAR reporting engine
- C. Include a step "Take a Snapshot" to capture the endpoint state to contain the threat for analysis
- D. Exclude the step "BAN malicious IP" to allow analysts to conduct and track the remediation
Answer: D
NEW QUESTION 101
Refer to the exhibit.
Which command was executed in PowerShell to generate this log?
- A. Get-EventLog -List
- B. Get-EventLog -LogName*
- C. Get-WinEvent -ListLog*
- D. Get-WinEvent -ListLog* -ComputerName localhost
Answer: B
NEW QUESTION 102 
Refer to the exhibit. An engineer configured this SOAR solution workflow to identify account theft threats and privilege escalation, evaluate risk, and respond by resolving the threat. This solution is handling more threats than Security analysts have time to analyze. Without this analysis, the team cannot be proactive and anticipate attacks. Which action will accomplish this goal?
- A. Exclude the step "Check for GeoIP location" to allow analysts to analyze the location and the associated risk based on asset criticality
- B. Include a step "Reporting" to alert the security department of threats identified by the SOAR reporting engine
- C. Include a step "Take a Snapshot" to capture the endpoint state to contain the threat for analysis
- D. Exclude the step "BAN malicious IP" to allow analysts to conduct and track the remediation
Answer: D
NEW QUESTION 103
An organization is using a PKI management server and a SOAR platform to manage the certificate lifecycle. The SOAR platform queries a certificate management tool to check all endpoints for SSL certificates that have either expired or are nearing expiration. Engineers are struggling to manage problematic certificates outside of PKI management since deploying certificates and tracking them requires searching server owners manually. Which action will improve workflow automation?
- A. Integrate a PKI solution within SOAR to create certificates within the SOAR engines to track, update, and monitor problematic certificates.
- B. Implement a new workflow within SOAR to create tickets in the incident response system, assign problematic certificate update requests to server owners, and register change requests.
- C. Implement a new workflow for SOAR to fetch a report of assets that are outside of the PKI zone, sort assets by certification management leads and automate alerts that updates are needed.
- D. Integrate a SOAR solution with Active Directory to pull server owner details from the AD and send an automated email for problematic certificates requesting updates.
Answer: C
NEW QUESTION 104
A SOC team is informed that a UK-based user will be traveling between three countries over the next 60 days. Having the names of the 3 destination countries and the user's working hours, what must the analyst do next to detect an abnormal behavior?
- A. Create a rule triggered by 1 successful VPN connection from any nondestination country
- B. Analyze the logs from all countries related to this user during the traveling period
- C. Create a rule triggered by multiple successful VPN connections from the destination countries
- D. Create a rule triggered by 3 failed VPN connection attempts in an 8-hour period
Answer: B
NEW QUESTION 105
A company's web server availability was breached by a DDoS attack and was offline for 3 hours because it was not deemed a critical asset in the incident response playbook. Leadership has requested a risk assessment of the asset. An analyst conducted the risk assessment using the threat sources, events, and vulnerabilities. Which additional element is needed to calculate the risk?
- A. event severity and likelihood
- B. assessment scope
- C. incident response playbook
- D. risk model framework
Answer: D
NEW QUESTION 106
Refer to the exhibit.
Cisco Advanced Malware Protection installed on an end-user desktop has automatically submitted a low prevalence file to the Threat Grid analysis engine for further analysis. What should be concluded from this report?
- A. The prioritized behavioral indicators of compromise justify the execution of the "ransomware" because the scores are low and indicate the likelihood that malicious ransomware has been detected.
- B. The prioritized behavioral indicators of compromise justify the execution of the "ransomware" because the scores are high and indicate the likelihood that malicious ransomware has been detected.
- C. The prioritized behavioral indicators of compromise do not justify the execution of the "ransomware" because the scores are high and do not indicate the likelihood of malicious ransomware.
- D. The prioritized behavioral indicators of compromise do not justify the execution of the "ransomware" because the scores do not indicate the likelihood of malicious ransomware.
Answer: B
NEW QUESTION 107
......
CyberOps Professional Free Certification Exam Material from BootcampPDF with 141 Questions: https://www.bootcamppdf.com/350-201_exam-dumps.html
Use Real 350-201 - 100% Cover Real Exam Questions: https://drive.google.com/open?id=1yxPafR0JdJ0dxkYnCf8nQ0wxNNmMaTNZ