According to NIST-SP800-61R2, why is it important to keep clocks synchronized?
A. event correlation
B. to link with other countries easily
C. to not lose track of time
D. to measure the effectiveness of an attack
Which type of analysis is done when all facts are available?
A. probabilistic
B. deterministic
C. static
D. dynamic
Refer to the exhibit.
Which technology generates this log?
A. NetFlow
B. IDS
C. web proxy
D. firewall
Which expression allows you to filter on network numbers?
A. ether [src|dst] host
B. gateway host
C. [src|dst] net
D. [tcp|udp] [src|dst] port
Which stakeholder is responsible for coordinating incident response among various business units, minimizing damage, and reporting to regulatory agencies?
A. management
B. public affairs and media relations
C. CSIRT
D. PSIRT
Which two elements are used for profiling a network? (Choose two.)
A. total throughout
B. session duration
C. running processes
D. OS fingerprint
E. listening ports
What do the Security Intelligence Events within the FMC allow an administrator to do?
A. See if a host is connecting to a known-bad domain.
B. Check for host-to-server traffic within your network.
C. View any malicious files that a host has downloaded.
D. Verify host-to-host traffic within your network.
Which IETF standard technology is useful to detect and analyze a potential security incident by recording session flows that occurs between hosts?
A. SFlow
B. NetFlow
C. NFlow
D. IPFIX
Which two compliance frameworks require that data be encrypted when it is transmitted over a public network? (Choose two.)
A. PCI
B. GLBA
C. HIPAA
D. SOX
E. COBIT
Which compliance framework applies to safeguarding a patient prescription list?
A. PCI
B. SOX
C. HIPAA
D. COBIT
Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 210-255 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.