Pass 350-201 Exam Latest Practice Questions Updated on Dec 29, 2023
Cisco 350-201 Study Guide Archives
Understanding helpful and specific pieces of 350-201 CISCO Performing CyberOps Using Cisco Security
The going with will be inspected in CISCO 350-201 exam dumps:
- Determine the imperatives while devouring APIs (for instance, rate restricted, breaks, furthermore, payload)
- Interpret essential contents (for instance, Python)
- Modify a gave content to computerize a security activities task
- Explain the basic HTTP reaction codes related with REST APIs
- Evaluate the pieces of a HTTP (reaction code, headers, body)
- Describe the standards of Infrastructure as Code
- Interpret API verification instruments: essential, custom token, and API keys
- Apply the standards of DevOps rehearses
- Describe segments of a CI/CD pipeline
- Compare ideas, stages, and instruments of organization and computerization
NEW QUESTION # 64
Refer to the exhibit.
An engineer received multiple reports from employees unable to log into systems with the error: The Group Policy Client service failed to logon - Access is denied. Through further analysis, the engineer discovered several unexpected modifications to system settings. Which type of breach is occurring?
- A. malware break
- B. data theft
- C. elevation of privileges
- D. denial-of-service
Answer: C
NEW QUESTION # 65
Engineers are working to document, list, and discover all used applications within an organization. During the regular assessment of applications from the HR backup server, an engineer discovered an unknown application. The analysis showed that the application is communicating with external addresses on a non- secure, unencrypted channel. Information gathering revealed that the unknown application does not have an owner and is not being used by a business unit. What are the next two steps the engineers should take in this investigation? (Choose two.)
- A. Initiate a triage meeting with department leads to determine if the application is owned internally or used by any business unit and document the asset owner.
- B. Identify who installed the application by reviewing the logs and gather a user access log from the HR department.
- C. Verify user credentials on the affected asset, modify passwords, and confirm available patches and updates are installed.
- D. Determine the type of data stored on the affected asset, document the access logs, and engage the incident response team.
Answer: A,D
NEW QUESTION # 66
How does Wireshark decrypt TLS network traffic?
- A. using an RSA public key
- B. by observing DH key exchange
- C. by defining a user-specified decode-as
- D. with a key log file using per-session secrets
Answer: D
NEW QUESTION # 67
A SOC analyst is notified by the network monitoring tool that there are unusual types of internal traffic on IP subnet 103.861.2117.0/24. The analyst discovers unexplained encrypted data files on a computer system that belongs on that specific subnet. What is the cause of the issue?
- A. phishing attack
- B. virus outbreak
- C. malware outbreak
- D. DDoS attack
Answer: C
NEW QUESTION # 68
Drag and drop the threat from the left onto the scenario that introduces the threat on the right. Not all options are used.
Answer:
Explanation:
NEW QUESTION # 69
A company launched an e-commerce website with multiple points of sale through internal and external e- stores. Customers access the stores from the public website, and employees access the stores from the intranet with an SSO. Which action is needed to comply with PCI standards for hardening the systems?
- A. Mask sales details
- B. Mask PAN numbers
- C. Encrypt personal data
- D. Encrypt access
Answer: C
NEW QUESTION # 70
What is the HTTP response code when the REST API information requested by the authenticated user cannot be found?
- A. 0
- B. 1
- C. 2
- D. 3
- E. 4
Answer: B
Explanation:
Explanation
Explanation/Reference: https://airbrake.io/blog/http-errors/401-unauthorized-error#:~:text=The%20401%20Unauthorized%
20Error%20is,client%20could%20not%20be%20authenticated.
NEW QUESTION # 71
Refer to the exhibit. What is occurring in this packet capture?
- A. TCP flood
- B. DNS flood
- C. DNS tunneling
- D. TCP port scan
Answer: A
NEW QUESTION # 72
Refer to the exhibit.
An employee is a victim of a social engineering phone call and installs remote access software to allow an "MS Support" technician to check his machine for malware. The employee becomes suspicious after the remote technician requests payment in the form of gift cards. The employee has copies of multiple, unencrypted database files, over 400 MB each, on his system and is worried that the scammer copied the files off but has no proof of it. The remote technician was connected sometime between 2:00 pm and 3:00 pm over https. What should be determined regarding data loss between the employee's laptop and the remote technician's system?
- A. The database files were intentionally corrupted, and encryption is possible
- B. The database files were disclosed
- C. No database files were disclosed
- D. The database files integrity was violated
Answer: D
NEW QUESTION # 73
A cloud engineer needs a solution to deploy applications on a cloud without being able to manage and control the server OS. Which type of cloud environment should be used?
- A. SaaS
- B. IaaS
- C. DaaS
- D. PaaS
Answer: B
NEW QUESTION # 74
The physical security department received a report that an unauthorized person followed an authorized individual to enter a secured premise. The incident was documented and given to a security specialist to analyze. Which step should be taken at this stage?
- A. Identify assets the attacker handled or acquired
- B. Change access controls to high risk assets in the enterprise
- C. Determine the assets to which the attacker has access
- D. Identify movement of the attacker in the enterprise
Answer: D
NEW QUESTION # 75
Refer to the exhibit.
For IP 192.168.1.209, what are the risk level, activity, and next step?
- A. critical risk level, malicious server IP, run in a sandboxed environment
- B. high risk level, anomalous periodic communication, quarantine with antivirus
- C. critical risk level, data exfiltration, isolate the device
- D. high risk level, malicious host, investigate further
Answer: B
NEW QUESTION # 76
Refer to the exhibit.
Two types of clients are accessing the front ends and the core database that manages transactions, access control, and atomicity. What is the threat model for the SQL database?
- A. An attacker can transfer data to an external server.
- B. An attacker can modify the access logs.
- C. An attacker can initiate a DoS attack.
- D. An attacker can read or change data.
Answer: C
NEW QUESTION # 77
Refer to the exhibit.
Where are the browser page rendering permissions displayed?
- A. x-test-debug
- B. x-frame-options
- C. x-content-type-options
- D. x-xss-protection
Answer: C
NEW QUESTION # 78
Refer to the exhibit.
The Cisco Secure Network Analytics (Stealthwatch) console alerted with "New Malware Server Discovered" and the IOC indicates communication from an end-user desktop to a Zeus C&C Server. Drag and drop the actions that the analyst should take from the left into the order on the right to investigate and remediate this IOC.
Answer:
Explanation:
NEW QUESTION # 79
......
350-201 Questions Prepare with Learning Information: https://freecert.test4sure.com/350-201-exam-materials.html