nerdexam
CiscoCisco

200-201 · Question #413

200-201 Question #413: Real Exam Question with Answer & Explanation

Sign in or unlock 200-201 to reveal the answer and full explanation for question #413. The question stem and answer options stay visible for context.

Submitted by certguy· Mar 6, 2026Host-Based Analysis

Question

An employee reports that someone has logged into their system and made unapproved changes, files are out of order, and several documents have been placed in the recycle bin. The security specialist reviewed the system logs, found nothing suspicious, and was not able to determine what occurred. The software is up to date; there are no alerts from antivirus and no failed login attempts. What is causing the lack of data visibility needed to detect the attack?

Options

  • AThe threat actor used a dictionary-based password attack to obtain credentials.
  • BThe threat actor gained access to the system by known credentials.
  • CThe threat actor used the teardrop technique to confuse and crash login services.
  • DThe threat actor used an unknown vulnerability of the operating system that went undetected.

Unlock 200-201 to see the answer

You've previewed enough free 200-201 questions. Unlock 200-201 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Log analysis#Incident response#Credential theft#Host compromise
Full 200-201 PracticeBrowse All 200-201 Questions