2023 350-201 Dumps PDF - 350-201 Real Exam Questions Answers
Valid 350-201 Test Answers & Cisco 350-201 Exam PDF
Understanding helpful and specific pieces of 350-201 CISCO Performing CyberOps Using Cisco Security
The going with will be inspected in CISCO 350-201 exam dumps:
- Evaluate the pieces of a HTTP (reaction code, headers, body)
- Modify a gave content to computerize a security activities task
- Apply the standards of DevOps rehearses
- Interpret API verification instruments: essential, custom token, and API keys
- Describe segments of a CI/CD pipeline
- Determine openings for mechanization and arrangement
- Determine the imperatives while devouring APIs (for instance, rate restricted, breaks, furthermore, payload)
- Interpret essential contents (for instance, Python)
- Compare ideas, stages, and instruments of organization and computerization
NEW QUESTION 44
Refer to the exhibit.
Two types of clients are accessing the front ends and the core database that manages transactions, access control, and atomicity. What is the threat model for the SQL database?
- A. An attacker can transfer data to an external server.
- B. An attacker can read or change data.
- C. An attacker can initiate a DoS attack.
- D. An attacker can modify the access logs.
Answer: C
NEW QUESTION 45
A SOC team is informed that a UK-based user will be traveling between three countries over the next 60 days. Having the names of the 3 destination countries and the user's working hours, what must the analyst do next to detect an abnormal behavior?
- A. Create a rule triggered by 3 failed VPN connection attempts in an 8-hour period
- B. Create a rule triggered by 1 successful VPN connection from any nondestination country
- C. Analyze the logs from all countries related to this user during the traveling period
- D. Create a rule triggered by multiple successful VPN connections from the destination countries
Answer: C
NEW QUESTION 46
Refer to the exhibit.
An engineer is performing static analysis of a file received and reported by a user. Which risk is indicated in this STIX?
- A. The file is redirecting users to the website that is downloading ransomware to encrypt files.
- B. The file is redirecting users to a website that is determining users' geographic location.
- C. The file is redirecting users to a website that harvests cookies and stored account information.
- D. The file is redirecting users to a website that requests privilege escalations from the user.
Answer: B
NEW QUESTION 47
A threat actor used a phishing email to deliver a file with an embedded macro. The file was opened, and a remote code execution attack occurred in a company's infrastructure. Which steps should an engineer take at the recovery stage?
- A. Determine the systems involved and deploy available patches
- B. Analyze event logs and restrict network access
- C. Identify the attack vector and update the IDS signature list
- D. Review access lists and require users to increase password complexity
Answer: B
NEW QUESTION 48
Refer to the exhibit.
IDS is producing an increased amount of false positive events about brute force attempts on the organization's mail server. How should the Snort rule be modified to improve performance?
- A. Tune the count and seconds threshold of the rule
- B. Block list of internal IPs from the rule
- C. Change the rule content match to case sensitive
- D. Set the rule to track the source IP
Answer: C
NEW QUESTION 49
An engineer receives a report that indicates a possible incident of a malicious insider sending company information to outside parties. What is the first action the engineer must take to determine whether an incident has occurred?
- A. Analyze the precursors and indicators
- B. Inform the computer security incident response team to investigate further
- C. Analyze environmental threats and causes
- D. Inform the product security incident response team to investigate further
Answer: A
NEW QUESTION 50
A security analyst receives an escalation regarding an unidentified connection on the Accounting A1 server within a monitored zone. The analyst pulls the logs and discovers that a Powershell process and a WMI tool process were started on the server after the connection was established and that a PE format file was created in the system directory. What is the next step the analyst should take?
- A. Isolate the server and perform forensic analysis of the file to determine the type and vector of a possible attack
- B. Identify the server owner through the CMDB and contact the owner to determine if these were planned and identifiable activities
- C. Review the server backup and identify server content and data criticality to assess the intrusion risk
- D. Perform behavioral analysis of the processes on an isolated workstation and perform cleaning procedures if the file is malicious
Answer: C
NEW QUESTION 51
A European-based advertisement company collects tracking information from partner websites and stores it on a local server to provide tailored ads. Which standard must the company follow to safeguard the resting data?
- A. GDPR
- B. PCI-DSS
- C. HIPAA
- D. Sarbanes-Oxley
Answer: A
Explanation:
Explanation/Reference: https://www.thesslstore.com/blog/10-data-privacy-and-encryption-laws-every-business-needs-to- know/
NEW QUESTION 52
Refer to the exhibit.
An organization is using an internal application for printing documents that requires a separate registration on the website. The application allows format-free user creation, and users must match these required conditions to comply with the company's user creation policy:
minimum length: 3
usernames can only use letters, numbers, dots, and underscores
usernames cannot begin with a number
The application administrator has to manually change and track these daily to ensure compliance. An engineer is tasked to implement a script to automate the process according to the company user creation policy. The engineer implemented this piece of code within the application, but users are still able to create format-free usernames. Which change is needed to apply the restrictions?
- A. automate the restrictions def automate_user(username, minlen)
- B. validate the restrictions, def validate_user(username, minlen)
- C. modify code to return error on restrictions def return false_user(username, minlen)
- D. modify code to force the restrictions, def force_user(username, minlen)
Answer: A
NEW QUESTION 53
A security manager received an email from an anomaly detection service, that one of their contractors has downloaded 50 documents from the company's confidential document management folder using a company- owned asset al039-ice-4ce687TL0500. A security manager reviewed the content of downloaded documents and noticed that the data affected is from different departments. What are the actions a security manager should take?
- A. Communicate with the contractor to identify the motives.
- B. Report to the incident response team.
- C. Measure confidentiality level of downloaded documents.
- D. Escalate to contractor's manager.
Answer: B
NEW QUESTION 54
Drag and drop the components from the left onto the phases of the CI/CD pipeline on the right.
Answer:
Explanation:
Reference:
https://www.densify.com/resources/continuous-integration-delivery-phases
NEW QUESTION 55
Drag and drop the components from the left onto the phases of the CI/CD pipeline on the right.
Answer:
Explanation:
Reference:
https://www.densify.com/resources/continuous-integration-delivery-phases
NEW QUESTION 56
Drag and drop the telemetry-related considerations from the left onto their cloud service models on the right.
Answer:
Explanation:
NEW QUESTION 57
An engineer received an incident ticket of a malware outbreak and used antivirus and malware removal tools to eradicate the threat. The engineer notices that abnormal processes are still occurring in the system and determines that manual intervention is needed to clean the infected host and restore functionality. What is the next step the engineer should take to complete this playbook step?
- A. Scan the host with updated signatures and remove temporary containment.
- B. Analyze the components of the infected hosts and associated business services.
- C. Scan the network to identify unknown assets and the asset owners.
- D. Analyze the impact of the malware and contain the artifacts.
Answer: B
NEW QUESTION 58
Refer to the exhibit.
Cisco Rapid Threat Containment using Cisco Secure Network Analytics (Stealthwatch) and ISE detects the threat of malware-infected 802.1x authenticated endpoints and places that endpoint into a Quarantine VLAN using Adaptive Network Control policy. Which telemetry feeds were correlated with SMC to identify the malware?
- A. NetFlow and event data
- B. event data and syslog data
- C. SNMP and syslog data
- D. NetFlow and SNMP
Answer: B
NEW QUESTION 59
Drag and drop the NIST incident response process steps from the left onto the actions that occur in the steps on the right.
Answer:
Explanation:
Reference:
https://www.securitymetrics.com/blog/6-phases-incident-response-plan
NEW QUESTION 60
Drag and drop the phases to evaluate the security posture of an asset from the left onto the activity that happens during the phases on the right.
Answer:
Explanation:
NEW QUESTION 61
Refer to the exhibit.
An engineer is investigating a case with suspicious usernames within the active directory. After the engineer investigates and cross-correlates events from other sources, it appears that the 2 users are privileged, and their creation date matches suspicious network traffic that was initiated from the internal network 2 days prior. Which type of compromise is occurring?
- A. compromised insider
- B. compromised network
- C. compromised database tables
- D. compromised root access
Answer: B
NEW QUESTION 62
......
350-201 Exam Dumps - PDF Questions and Testing Engine: https://www.dumpsquestion.com/350-201-exam-dumps-collection.html