Pass Your 350-201 Exam at the First Try with 100% Real Exam Questions [Q14-Q32]

Share

Pass Your 350-201 Exam at the First Try with 100% Real Exam Questions

New Cisco 350-201 Dumps & Questions Updated on 2024


Cisco 350-201 exam is a certification test for individuals who want to demonstrate their skills in performing cyber operations using Cisco security technologies. 350-201 exam is designed for professionals who are responsible for designing, implementing, and managing security solutions in complex environments. Passing 350-201 exam will validate that the candidate has the knowledge and skills required to identify security threats, develop security policies, and implement security controls to protect against cyber attacks.

 

NEW QUESTION # 14
Refer to the exhibit.

Rapid Threat Containment using Cisco Secure Network Analytics (Stealthwatch) and ISE detects the threat of malware-infected 802.1x authenticated endpoints and places that endpoint into a quarantine VLAN using Adaptive Network Control policy. Which method was used to signal ISE to quarantine the endpoints?

  • A. SNMP
  • B. syslog
  • C. pxGrid
  • D. REST API

Answer: D


NEW QUESTION # 15
Refer to the exhibit.

A security analyst needs to investigate a security incident involving several suspicious connections with a possible attacker. Which tool should the analyst use to identify the source IP of the offender?

  • A. malware analysis
  • B. SIEM
  • C. firewall manager
  • D. packet sniffer

Answer: D

Explanation:
In the context of investigating a security incident involving suspicious connections, a packet sniffer is the most appropriate tool for identifying the source IP of the offender. A packet sniffer captures and analyzes network traffic, allowing the analyst to see the details of each packet that is transmitted over the network. This includes source and destination IP addresses, port numbers, protocols used, and the content of the data being sent. By examining the captured data, the analyst can identify the source IP address of the suspicious connections and take appropriate action. This is particularly useful in scenarios where an attacker might be attempting to communicate with compromised systems within the network.


NEW QUESTION # 16
An organization lost connectivity to critical servers, and users cannot access business applications and internal websites. An engineer checks the network devices to investigate the outage and determines that all devices are functioning. Drag and drop the steps from the left into the sequence on the right to continue investigating this issue. Not all options are used.

Answer:

Explanation:


NEW QUESTION # 17
An engineer is investigating several cases of increased incoming spam emails and suspicious emails from the HR and service departments. While checking the event sources, the website monitoring tool showed several web scraping alerts overnight. Which type of compromise is indicated?

  • A. phishing
  • B. privilege escalation
  • C. dumpster diving
  • D. social engineering

Answer: A

Explanation:
The combination of increased incoming spam emails and web scraping alerts suggests a phishing attempt.
Phishing is a type of social engineering attack where attackers send fraudulent messages designed to trick individuals into revealing sensitive information or deploying malicious software. Web scraping can be used to gather email addresses for such campaigns


NEW QUESTION # 18
An engineer received an incident ticket of a malware outbreak and used antivirus and malware removal tools to eradicate the threat. The engineer notices that abnormal processes are still occurring in the system and determines that manual intervention is needed to clean the infected host and restore functionality. What is the next step the engineer should take to complete this playbook step?

  • A. Scan the host with updated signatures and remove temporary containment.
  • B. Analyze the components of the infected hosts and associated business services.
  • C. Scan the network to identify unknown assets and the asset owners.
  • D. Analyze the impact of the malware and contain the artifacts.

Answer: B


NEW QUESTION # 19
Refer to the exhibit.

Which command was executed in PowerShell to generate this log?

  • A. Get-EventLog -LogName*
  • B. Get-WinEvent -ListLog*
  • C. Get-EventLog -List
  • D. Get-WinEvent -ListLog* -ComputerName localhost

Answer: A


NEW QUESTION # 20
A threat actor has crafted and sent a spear-phishing email with what appears to be a trustworthy link to the site of a conference that an employee recently attended. The employee clicked the link and was redirected to a malicious site through which the employee downloaded a PDF attachment infected with ransomware. The employee opened the attachment, which exploited vulnerabilities on the desktop. The ransomware is now installed and is calling back to its command and control server. Which security solution is needed at this stage to mitigate the attack?

  • A. endpoint security solution
  • B. network security solution
  • C. email security solution
  • D. web security solution

Answer: A

Explanation:
At this stage of a ransomware attack, where the ransomware is installed and calling back to its command and control server, an endpoint security solution is needed to mitigate the attack. Endpoint security solutions can detect and respond to threats at the device level, isolate infected machines, and prevent the spread of ransomware within the network4.


NEW QUESTION # 21
Drag and drop the actions below the image onto the boxes in the image for the actions that should be taken during this playbook step. Not all options are used.

Answer:

Explanation:


NEW QUESTION # 22
A SOC analyst detected a ransomware outbreak in the organization coming from a malicious email attachment. Affected parties are notified, and the incident response team is assigned to the case. According to the NIST incident response handbook, what is the next step in handling the incident?

  • A. Collect evidence and maintain a chain-of-custody during further analysis.
  • B. Create a follow-up report based on the incident documentation.
  • C. Perform a vulnerability assessment to find existing vulnerabilities.
  • D. Eradicate malicious software from the infected machines.

Answer: D

Explanation:
According to the NIST incident response handbook, after detecting a ransomware outbreak and notifying the affected parties, the next step is to eradicate the malicious software from the infected machines. This involves removing the ransomware and any associated malware to prevent further encryption or spread of the infection3


NEW QUESTION # 23
Drag and drop the NIST incident response process steps from the left onto the actions that occur in the steps on the right.

Answer:

Explanation:


NEW QUESTION # 24
An engineer is developing an application that requires frequent updates to close feedback loops and enable teams to quickly apply patches. The team wants their code updates to get to market as often as possible. Which software development approach should be used to accomplish these goals?

  • A. continuous monitoring
  • B. continuous delivery
  • C. continuous integration
  • D. continuous deployment

Answer: B

Explanation:
Continuous delivery is a software development approach that enables teams to produce software in short cycles, ensuring that the software can be reliably released at any time. It aims to build, test, and release software with greater speed and frequency. This approach helps in closing feedback loops and enables teams to quickly apply patches, making it ideal for situations where code updates need to reach the market as often as possible


NEW QUESTION # 25
Refer to the exhibit.

How must these advisories be prioritized for handling?

  • A. The highest priority for handling depends on the type of institution deploying the devices
  • B. Vulnerability #1 and vulnerability #2 have the same priority
  • C. Vulnerability #2 is the highest priority for every type of institution
  • D. Vulnerability #1 is the highest priority for every type of institution

Answer: A

Explanation:
Prioritizing vulnerabilities for handling is a critical process that depends on various factors, including the nature of the institution and the context in which the devices are deployed. Vulnerability #1, which affects the Command Line Interpreter (CLI) of ACME Super Firewall, could allow an attacker to execute arbitrary commands with administrative rights. This type of vulnerability is particularly severe because it could lead to complete system compromise. However, it requires the attacker to be logged in to the device, which adds a layer of difficulty for exploitation.
Vulnerability #2 affects the web-based management interface of ACME Router models 1010 and 1020, allowing an attacker to bypass authorization checks. This vulnerability is also critical as it can lead to unauthorized access to sensitive information and system configuration. Unlike Vulnerability #1, it does not require the attacker to be logged in, making it easier to exploit.
The prioritization of these vulnerabilities would depend on the specific deployment scenario of the institution.
For example, an institution that heavily relies on remote management of devices may prioritize Vulnerability
#2 higher due to its remote exploitability. Conversely, an institution with strict access controls and limited remote access might prioritize Vulnerability #1 due to the potential for internal threats.


NEW QUESTION # 26
An engineer notices that unauthorized software was installed on the network and discovers that it was installed by a dormant user account. The engineer suspects an escalation of privilege attack and responds to the incident. Drag and drop the activities from the left into the order for the response on the right.

Answer:

Explanation:


NEW QUESTION # 27
Refer to the exhibit.

An engineer must tune the Cisco IOS device to mitigate an attack that is broadcasting a large number of ICMP packets. The attack is sending the victim's spoofed source IP to a network using an IP broadcast address that causes devices in the network to respond back to the source IP address. Which action does the engineer recommend?

  • A. Use logging trap 6
  • B. Use command ip verify reverse-path interface
  • C. Use global configuration command service tcp-keepalives-out
  • D. Use subinterface command no ip directed-broadcast

Answer: B


NEW QUESTION # 28
After a recent malware incident, the forensic investigator is gathering details to identify the breach and causes. The investigator has isolated the affected workstation. What is the next step that should be taken in this investigation?

  • A. Review audit logs for privilege escalation events.
  • B. Inspect registry entries for recently executed files.
  • C. Compare workstation configuration and asset configuration policy to identify gaps.
  • D. Analyze the applications and services running on the affected workstation.

Answer: B


NEW QUESTION # 29
Drag and drop the mitigation steps from the left onto the vulnerabilities they mitigate on the right.

Answer:

Explanation:


NEW QUESTION # 30
Refer to the exhibit.

Which data format is being used?

  • A. CSV
  • B. XML
  • C. JSON
  • D. HTML

Answer: B

Explanation:
The data format being used in the exhibit is XML (Extensible Markup Language). This can be determined by the presence of tags enclosed in angle brackets (<>), which define the start and end of an element, as well as the hierarchical structure that organizes the data within nested elements. In this case, there are "employee" elements nested within an "employees" root element, each containing "lastname" and "firstname" child elements with corresponding closing tags.
References:
* Cisco's training on Performing CyberOps Using Cisco Security Technologies would cover data formats like XML as part of understanding how to handle and analyze security data.
* The official Cisco Certified CyberOps Associate certification resources would include information on various data formats encountered in cybersecurity operations.


NEW QUESTION # 31
Refer to the exhibit.

An engineer is performing a static analysis on a malware and knows that it is capturing keys and webcam events on a company server. What is the indicator of compromise?

  • A. The malware has moved to harvesting cookies and stored account information from major browsers and configuring a reverse proxy for intercepting network activity.
  • B. The malware is a ransomware querying for installed anti-virus products and operating systems to encrypt and render unreadable until payment is made for file decryption.
  • C. The malware contains an encryption and decryption routine to hide URLs/IP addresses and is storing the output of loggers and webcam captures in locally encrypted files for retrieval.
  • D. The malware is performing comprehensive fingerprinting of the host, including a processor, motherboard manufacturer, and connected removable storage.

Answer: B


NEW QUESTION # 32
......

Updated Exam 350-201 Dumps with New Questions: https://www.examcollectionpass.com/Cisco/350-201-practice-exam-dumps.html

Dumps to Pass your 350-201 Exam with 100% Real Questions and Answers: https://drive.google.com/open?id=14JkflVoZR-UzFGe0793mMLCIBq_08kRg