A user received a malicious email attachment named "DS045-report1122345.exe" and executed it.
In which step of the Cyber Kill Chain is this event?
A. reconnaissanceWhat is indicated by an increase in IPv4 traffic carrying protocol 41 ?
A. additional PPTP traffic due to Windows clientsAn automotive company provides new types of engines and special brakes for rally sports cars. The company has a database of inventions and patents for their engines and technical information Customers can access the database through the company's website after they register and identify themselves.
Which type of protected data is accessed by customers?
A. IP dataA security incident occurred with the potential of impacting business services.
Who performs the attack?
A. malware authorA company is using several network applications that require high availability and responsiveness, such that milliseconds of latency on network traffic is not acceptable. An engineer needs to analyze the network and identify ways to improve traffic movement to minimize delays.
Which information must the engineer obtain for this analysis?
A. total throughput on the interface of the router and NetFlow recordsAn analyst performs traffic analysis to detect data exfiltration and identifies a high frequency of DNS requests in a small period of time.
Which technology makes this behavior feasible?
A. access control listWhich security monitoring data type is associated with application server logs?
A. transaction dataA network engineer informed a security team of a large amount of traffic and suspicious activity from an unknown source to the company DMZ server The security team reviewed the data and identified a potential DDoS attempt According to NIST, at which phase of incident response is the security team?
A. containment and eradicationWhich two elements are assets in the role of attribution in an investigation? (Choose two.)
A. contextWhat should a security analyst consider when comparing inline traffic interrogation with traffic tapping to determine which approach to use in the network?
A. Tapping interrogation replicates signals to a separate port for analyzing trafficNowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 200-201 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.