200-201 Exam Questions
563 real 200-201 exam questions with expert-verified answers and explanations. Page 5 of 12.
- Question #204Network Intrusion Analysis
Refer to the exhibit. A company employee is connecting to mail google.com from an endpoint device. The website is loaded but with an error. What is occurring?
SSL/TLS errorsdigital certificatestrusted rootsweb security - Question #205Security Monitoring
An analyst is using the SIEM platform and must extract a custom property from a Cisco device and capture the phrase, "File: Clean." Which regex must the analyst import?
regexSIEMlog parsingevent correlation - Question #206Security Concepts
What describes the concept of data consistently and readily being accessible for legitimate users?
availabilityCIA triadsecurity concepts - Question #207Network Intrusion Analysis
Refer to the exhibit. Which frame numbers contain a file that is extractable via TCP stream within Wireshark?
WiresharkTCP streampacket analysisnetwork forensics - Question #208Security Policies and Procedures
Refer to the exhibit. Which stakeholders must be involved when a company workstation is compromised?
incident responsestakeholder managementsecurity policiesorganizational roles - Question #209Security Concepts
How does an attack surface differ from an attack vector?
attack surfaceattack vectorvulnerability - Question #210Security Monitoring
A security analyst notices a sudden surge of incoming traffic and detects unknown packets from unknown senders. After further investigation, the analyst learns that customers claim...
incident responseNIST SP800-61detection and analysis - Question #211Security Concepts
Which vulnerability type is used to read, write, or erase information from a database?
SQL injectionweb vulnerabilitiesdatabase attacks - Question #212Security Policies and Procedures
An automotive company provides new types of engines and special brakes for rally sports cars. The company has a database of inventions and patents for their engines and technical i...
data classificationintellectual propertyIP data - Question #213Security Concepts
According to the September 2020 threat intelligence feeds a new malware called Egregor was introduced and used in many attacks. Distnbution of Egregor is pnmanly through a Cobalt S...
ransomwaremalwaredata exfiltrationthreat intelligence - Question #214Host-Based Analysis
Syslog collecting software is installed on the server. For the log containment, a disk with FAT type partition is used. An engineer determined that log files are being corrupted wh...
file systemsFATNTFSlog managementhost security - Question #215Network Intrusion Analysis
What are two categories of DDoS attacks? (Choose two.)
DDoS attacksreflected DDoSdirect DDoSnetwork attacks - Question #216Security Concepts
What is an advantage of symmetric over asymmetric encryption?
symmetric encryptionasymmetric encryptioncryptographyencryption performance - Question #217Network Intrusion Analysis
What are two denial-of-service (DoS) attacks? (Choose two)
DoS attacksSYN floodteardrop attacknetwork attacks - Question #218Security Concepts
What is the difference between a threat and an exploit?
threatexploitvulnerability - Question #219Security Concepts
How does TOR alter data content during transit?
TORanonymity networksencryption - Question #220CompTIA Security+ Domain 1: Threats, Attacks, and Vulnerabilities - Understanding and differentiating between core security terminology including threats, risks, vulnerabilities, and exploits.
Drag and Drop Question Drag and drop the security concept from the left onto the example of that concept on the right. Answer:
Security FundamentalsThreat vs RiskVulnerability ManagementCore Security Concepts - Question #221Security Concepts
What is a collection of compromised machines that attackers use to carry out a DDoS attack?
botnetDDoSmalware - Question #222Security Policies and Procedures
Which type of access control depends on the job function of the user?
access controlRBACjob roles - Question #223Security Monitoring
The security team has detected an ongoing spam campaign targeting the organization. The team's approach is to push back the cyber kill chain and mitigate ongoing incidents. At whic...
cyber kill chainspamincident responsedelivery phase - Question #224Security Concepts
What describes the defense-in-depth principle?
defense-in-depthsecurity architecturenetwork segmentation - Question #225Security Monitoring
Refer to the exhibit. A workstation downloads a malicious docx file from the Internet and a copy is sent to FTDv. The FTDv sends the file hash to FMC and the tile event is recorded...
data visibilitymalware analysisthreat detectionsecurity controls - Question #226Security Concepts
What is the impact of encryption?
encryptionconfidentialitydata security - Question #227Host-Based Analysis
An engineer is analyzing a recent breach where confidential documents were altered and stolen by the receptionist. Further analysis shows that the threat actor connected an externa...
incident responseattributionforensicsinsider threat - Question #228Network Intrusion Analysis
Refer to the exhibit. During the analysis of a suspicious scanning activity incident, an analyst discovered multiple local TCP connection events. Which technology provided these lo...
log analysisTCP connectionsscanning activityfirewall logs - Question #229Network Intrusion Analysis
Refer to the exhibit. An analyst was given a PCAP file, which is associated with a recent intrusion event in the company FTP server. Which display filters should the analyst use to...
Wiresharkpacket analysisFTPTCP ports - Question #230Network Intrusion Analysis
Refer to the exhibit. A network administrator is investigating suspicious network activity by analyzing captured traffic. An engineer notices abnormal behavior and discovers that t...
HTTP headersuser agentdata exfiltrationnetwork analysis - Question #231Security Concepts
A company encountered a breach on its web servers using IIS 7.5. During the investigation, an engineer discovered that an attacker read and altered the data on a secure communicati...
TLS downgrade attackTLS 1.3cryptographic protocolssecure communication - Question #232Security Concepts
What is the difference between discretionary access control (DAC) and role-based access control (RBAC)?
DACRBACaccess controlauthorization - Question #233Security Concepts
Which technology prevents end-device to end-device IP traceability?
NATPATIP traceabilitynetwork privacy - Question #234Security Concepts
What are the two differences between stateful and deep packet inspection? (Choose two)
stateful inspectiondeep packet inspectionfirewallsnetwork security - Question #235Security Concepts
Which type of verification consists of using tools to compute the message digest of the original and copied data, then comparing the similarity of the digests?
data integrityhashingmessage digestforensics - Question #236Security Monitoring
What is the difference between inline traffic interrogation (TAPS) and traffic mirroring (SPAN)?
TAPSSPANtraffic mirroringnetwork monitoring - Question #237Security Concepts
Which information must an organization use to understand the threats currently targeting the organization?
threat intelligencethreat landscapesecurity information - Question #238Security Policies and Procedures
What is threat hunting?
threat huntingvulnerability assessmentrisk mitigationsecurity management - Question #239Security Concepts
An engineer is working with the compliance teams to identify the data passing through the network. During analysis, the engineer informs the compliance team that external penmeter...
PIIcopyrightdata classificationsensitive data - Question #240Security Monitoring
What describes the impact of false-positive alerts compared to false-negative alerts?
false positivefalse negativesecurity alertsalert fatigue - Question #241Host-Based Analysis
Refer to the exhibit. An engineer received a ticket about a slowed-down web application. The engineer runs the #netstat - an command. How must the engineer interpret the results?
netstatdenial-of-serviceDoS attacknetwork troubleshooting - Question #242Network Intrusion Analysis
When an event is investigated, which type of data provides the investigate capability to determine if data exfiltration has occurred?
full packet capturedata exfiltrationforensicsnetwork evidence - Question #243Security Concepts
What is the difference between deep packet inspection and stateful inspection?
deep packet inspectionstateful inspectionOSI modelfirewall capabilities - Question #244Security Monitoring
What is obtained using NetFlow?
NetFlowsession datanetwork telemetryflow data - Question #245Security Monitoring
How does statistical detection differ from rule-based detection?
statistical detectionrule-based detectionIDS/IPSanomaly detection - Question #246Network Intrusion Analysis
Refer to the exhibit. What must be interpreted from this packet capture?
packet captureTCP/IPIP addressesport numbersnetwork interpretation - Question #247Security Concepts
What is a benefit of using asymmetric cryptography?
asymmetric cryptographypublic key infrastructuresecure communicationconfidentiality - Question #248Security Concepts
An organization is cooperating with several third-party companies. Data exchange is on an unsecured channel using port 80 Internal employees use the FTP service to upload and downl...
X.509 certificatesTLS/SSLconfidentialityintegritysecure communication - Question #249Security Concepts
A security engineer notices confidential data being exfiltrated to a domain 'Ransome4144- mware73-978' address that is attributed to a known advanced persistent threat group. The e...
Cyber Kill ChainAPTdata exfiltrationincident classification - Question #250Security Monitoring
How does agentless monitoring differ from agent-based monitoring?
agent-based monitoringagentless monitoringlog data collection - Question #251Security Monitoring
Which of these describes SOC metrics in relation to security incidents?
SOC metricsincident detection timesecurity incidents - Question #252Network Intrusion Analysis
What is the difference between the ACK flag and the RST flag?
TCP flagsACK flagRST flagnetwork protocols - Question #253Network Intrusion Analysis
Refer to the exhibit. An engineer is analyzing a PCAP file after a recent breach. An engineer identified that the attacker used an aggressive ARP scan to scan the hosts and found w...
PCAP analysisSSH brute forcenetwork reconnaissanceARP scan