What is the name of the technology that searches for and reports on known weaknesses and flaws present in an organization's IT infrastructure?
A. vulnerability scannerA SOC analyst detected connections to known C&C and port scanning activity to main HR database servers from one of the HR endpoints, via Cisco StealthWatch.
What are the two next steps of the SOC team according to the NIST.SP800- 61 incident handling process? (Choose two.)
A. Update antivirus signature databases on affected endpoints to block connections to C&C.What are two denial of service attacks? (Choose two.)
A. MITM
Refer to the exhibit. A security engineer receives several alerts from the SNORT IPS/IDS reporting malicious traffic.
What should the engineer understand by examining the SNORT logs?
A. A remote threat performs an EternalBlue attack on a Windows system on several ports.Which scenario describes a social engineering attack?
A. Malicious insider trying to gather information on company securityWhich action matches the weaponization step of the Cyber Kill Chain Model?
A. Develop a specific malware to exploit a vulnerable server.Syslog collecting software is installed on the server For the log containment, a disk with FAT type partition is used An engineer determined that log files are being corrupted when the 4 GB tile size is exceeded.
Which action resolves the issue?
A. Add space to the existing partition and lower the retention penod.Refer to the exhibit.

What is the potential threat identified in this Stealthwatch dashboard?
A. Host 10.201.3.149 is sending data to 152.46.6.91 using TCP/443.Refer to the exhibit.

An engineer is analyzing a PCAP file after a recent breach An engineer identified that the attacker used an aggressive ARP scan to scan the hosts and found web and SSH servers. Further analysis showed several SSH Server Banner and Key Exchange Initiations. The engineer cannot see the exact data being transmitted over an encrypted channel and cannot identify how the attacker gained access.
How did the attacker gain access?
A. by using the buffer overflow in the URL catcher feature for SSHAccording to the NIST SP 800-86.
which two types of data are considered volatile? (Choose two.)
A. swap filesNowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 200-201 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.