Real 350-201 dumps Accurate Questions and Answers with Free and Fast Updates
Real 350-201 Quesions Pass Certification Exams Easily
NEW QUESTION 69
An engineer received multiple reports from users trying to access a company website and instead of landing on the website, they are redirected to a malicious website that asks them to fill in sensitive personal dat a. Which type of attack is occurring?
- A. Domain Name System poisoning
- B. teardrop attack
- C. session hijacking attack
- D. Address Resolution Protocol poisoning
Answer: A
NEW QUESTION 70
An engineer implemented a SOAR workflow to detect and respond to incorrect login attempts and anomalous user behavior. Since the implementation, the security team has received dozens of false positive alerts and negative feedback from system administrators and privileged users. Several legitimate users were tagged as a threat and their accounts blocked, or credentials reset because of unexpected login times and incorrectly typed credentials. How should the workflow be improved to resolve these issues?
- A. Add a confirmation step through which SOAR informs the affected user and asks them to confirm whether they made the attempts
- B. Change the SOAR configuration flow to remove the automatic remediation that is increasing the false positives and triggering threats
- C. Increase incorrect login tries and tune anomalous user behavior not to affect privileged accounts
- D. Meet with privileged users to increase awareness and modify the rules for threat tags and anomalous behavior alerts
Answer: B
NEW QUESTION 71
An organization had an incident with the network availability during which devices unexpectedly malfunctioned. An engineer is investigating the incident and found that the memory pool buffer usage reached a peak before the malfunction. Which action should the engineer take to prevent this issue from reoccurring?
- A. Enable memory threshold notifications.
- B. Disable CPU threshold trap toward the SNMP server.
- C. Enable memory tracing notifications.
- D. Disable memory limit.
Answer: A
NEW QUESTION 72
A SOC team receives multiple alerts by a rule that detects requests to malicious URLs and informs the incident response team to block the malicious URLs requested on the firewall. Which action will improve the effectiveness of the process?
- A. Block local to remote HTTP/HTTPS requests on the firewall for users who triggered the rule.
- B. Create an automation script for blocking URLs on the firewall when the rule is triggered.
- C. Inform the incident response team by enabling an automated email response when the rule is triggered.
- D. Inform the user by enabling an automated email response when the rule is triggered.
Answer: A
NEW QUESTION 73
A company recently started accepting credit card payments in their local warehouses and is undergoing a PCI audit. Based on business requirements, the company needs to store sensitive authentication data for 45 days. How must data be stored for compliance?
- A. post-authorization by non-issuing entities if the data is encrypted and securely stored
- B. by issuers and issuer processors if there is a legitimate reason
- C. post-authorization by non-issuing entities if there is a documented business justification
- D. by entities that issue the payment cards or that perform support issuing services
Answer: A
NEW QUESTION 74
A European-based advertisement company collects tracking information from partner websites and stores it on a local server to provide tailored ads. Which standard must the company follow to safeguard the resting data?
- A. GDPR
- B. PCI-DSS
- C. HIPAA
- D. Sarbanes-Oxley
Answer: A
Explanation:
Explanation/Reference: https://www.thesslstore.com/blog/10-data-privacy-and-encryption-laws-every-business-needs-to- know/
NEW QUESTION 75
Which command does an engineer use to set read/write/execute access on a folder for everyone who reaches the resource?
- A. chmod 666
- B. chmod 777
- C. chmod 774
- D. chmod 775
Answer: B
Explanation:
Explanation/Reference: https://www.pluralsight.com/blog/it-ops/linux-file-permissions
NEW QUESTION 76
Drag and drop the cloud computing service descriptions from the left onto the cloud service categories on the right.
Answer:
Explanation:
NEW QUESTION 77
A threat actor has crafted and sent a spear-phishing email with what appears to be a trustworthy link to the site of a conference that an employee recently attended. The employee clicked the link and was redirected to a malicious site through which the employee downloaded a PDF attachment infected with ransomware. The employee opened the attachment, which exploited vulnerabilities on the desktop. The ransomware is now installed and is calling back to its command and control server. Which security solution is needed at this stage to mitigate the attack?
- A. email security solution
- B. web security solution
- C. endpoint security solution
- D. network security solution
Answer: D
NEW QUESTION 78
A SOC analyst is investigating a recent email delivered to a high-value user for a customer whose network their organization monitors. The email includes a suspicious attachment titled "Invoice RE: 0004489". The hash of the file is gathered from the Cisco Email Security Appliance. After searching Open Source Intelligence, no available history of this hash is found anywhere on the web. What is the next step in analyzing this attachment to allow the analyst to gather indicators of compromise?
- A. Obtain a copy of the file for detonation in a sandbox
- B. Run and analyze the DLP Incident Summary Report from the Email Security Appliance
- C. Investigate further in open source repositories using YARA to find matches
- D. Ask the company to execute the payload for real time analysis
Answer: A
NEW QUESTION 79
Which command does an engineer use to set read/write/execute access on a folder for everyone who reaches the resource?
- A. chmod 666
- B. chmod 777
- C. chmod 774
- D. chmod 775
Answer: B
NEW QUESTION 80
Refer to the exhibit.
An engineer received a report that an attacker has compromised a workstation and gained access to sensitive customer data from the network using insecure protocols. Which action prevents this type of attack in the future?
- A. Use VLANs to segregate zones and the firewall to allow only required services and secured protocols
- B. Deploy a SOAR solution and correlate log alerts from customer zones
- C. Deploy IDS within sensitive areas and continuously update signatures
- D. Use syslog to gather data from multiple sources and detect intrusion logs for timely responses
Answer: A
NEW QUESTION 81 
Refer to the exhibit. Cisco Advanced Malware Protection installed on an end-user desktop has automatically submitted a low prevalence file to the Threat Grid analysis engine for further analysis. What should be concluded from this report?
- A. The prioritized behavioral indicators of compromise do not justify the execution of the "ransomware" because the scores do not indicate the likelihood of malicious ransomware.
- B. The prioritized behavioral indicators of compromise justify the execution of the "ransomware" because the scores are high and indicate the likelihood that malicious ransomware has been detected.
- C. The prioritized behavioral indicators of compromise justify the execution of the "ransomware" because the scores are low and indicate the likelihood that malicious ransomware has been detected.
- D. The prioritized behavioral indicators of compromise do not justify the execution of the "ransomware" because the scores are high and do not indicate the likelihood of malicious ransomware.
Answer: B
NEW QUESTION 82
Refer to the exhibit.
Where does it signify that a page will be stopped from loading when a scripting attack is detected?
- A. x-frame-options
- B. x-xss-protection
- C. x-test-debug
- D. x-content-type-options
Answer: B
NEW QUESTION 83
An engineer is developing an application that requires frequent updates to close feedback loops and enable teams to quickly apply patches. The team wants their code updates to get to market as often as possible. Which software development approach should be used to accomplish these goals?
- A. continuous integration
- B. continuous monitoring
- C. continuous deployment
- D. continuous delivery
Answer: D
NEW QUESTION 84
Refer to the exhibit.
Rapid Threat Containment using Cisco Secure Network Analytics (Stealthwatch) and ISE detects the threat of malware-infected 802.1x authenticated endpoints and places that endpoint into a quarantine VLAN using Adaptive Network Control policy. Which method was used to signal ISE to quarantine the endpoints?
- A. SNMP
- B. syslog
- C. pxGrid
- D. REST API
Answer: D
NEW QUESTION 85
According to GDPR, what should be done with data to ensure its confidentiality, integrity, and availability?
- A. Conduct a data protection impact assessment
- B. Perform awareness testing
- C. Conduct penetration testing
- D. Perform a vulnerability assessment
Answer: A
Explanation:
Explanation/Reference: https://apdcat.gencat.cat/web/.content/03-documentacio/ Reglament_general_de_proteccio_de_dades/documents/DPIA-Guide.pdf
NEW QUESTION 86
Refer to the exhibit.
A threat actor behind a single computer exploited a cloud-based application by sending multiple concurrent API requests. These requests made the application unresponsive. Which solution protects the application from being overloaded and ensures more equitable application access across the end-user community?
- A. Limit the number of API calls that a single client is allowed to make
- B. Increase the application cache of the total pool of active clients that call the API
- C. Reduce the amount of data that can be fetched from the total pool of active clients that call the API
- D. Add restrictions on the edge router on how often a single client can access the API
Answer: A
NEW QUESTION 87
An organization installed a new application server for IP phones. An automated process fetched user credentials from the Active Directory server, and the application will have access to on-premises and cloud services. Which security threat should be mitigated first?
- A. aligning access control policies
- B. attack using default accounts
- C. data exposure from backups
- D. exfiltration during data transfer
Answer: D
NEW QUESTION 88
The SIEM tool informs a SOC team of a suspicious file. The team initializes the analysis with an automated sandbox tool, sets up a controlled laboratory to examine the malware specimen, and proceeds with behavioral analysis. What is the next step in the malware analysis process?
- A. Unpack the specimen and perform memory forensics.
- B. Document findings and clean-up the laboratory.
- C. Contain the subnet in which the suspicious file was found.
- D. Perform static and dynamic code analysis of the specimen.
Answer: A
NEW QUESTION 89 
Refer to the exhibit. Where are the browser page rendering permissions displayed?
- A. x-content-type-options
- B. x-frame-options
- C. x-xss-protection
- D. x-test-debug
Answer: A
Explanation:
Explanation
Explanation/Reference: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Content-Type-Options
NEW QUESTION 90
What is a limitation of cyber security risk insurance?
- A. It does not cover the costs to restore stolen identities as a result of a cyber attack
- B. It does not cover the costs of damage done by third parties as a result of a cyber attack
- C. It does not cover the costs to hire a public relations company to help deal with a cyber attack
- D. It does not cover the costs to hire forensics experts to analyze the cyber attack
Answer: A
NEW QUESTION 91
......
Preparation Process
If you want to learn all the details of the exam content and be ready for Cisco 350-201, you can take the Performing CyberOps Using Cisco Security Technologies v1.0 course. This is the official training option, which is available on the vendor’s website. It covers the information about the cybersecurity operations fundamentals and methods as well as automation. With the help of this course, an interested individual is able to learn the foundational concepts and know how to leverage playbooks to formulate Incident Response. It is led by a certified instructor and available in almost any country in the world. It lasts for 5 days of hands-on practice and 3 days of covering content with challenges and practice. Before enrolling for the training, it is recommended that you possess a good knowledge of the content covered in the associate-level CyberOps course as well as have familiarity with UNIX/Linux shells & shell commands. Additionally, you should have a basic understanding of scripting when JavaScript, Python, or PHP are used.
350-201 Dumps are Available for Instant Access: https://www.examcollectionpass.com/Cisco/350-201-practice-exam-dumps.html
Practice with these 350-201 dumps Certification Sample Questions: https://drive.google.com/open?id=14JkflVoZR-UzFGe0793mMLCIBq_08kRg