350-201 Practice Questions
128 real 350-201 exam questions with expert-verified answers and explanations. Page 1 of 3.
- Question #1Network Intrusion Analysis
Refer to the exhibit. An engineer must tune the Cisco IOS device to mitigate an attack that is broadcasting a large number of ICMP packets. The attack is sending the victim's spoof...
Smurf attackdirected broadcastICMP floodIP spoofing - Question #2Security Monitoring
Refer to the exhibit. An engineer is analyzing this Vlan0392-int12-239.pcap file in Wireshark after detecting a suspicious network activity. The origin header for the direct IP con...
STIXWebSocketdata exfiltrationobfuscated payload - Question #3Fundamentals
What do 2xx HTTP response codes indicate for REST APIs?
HTTP status codesREST API2xx responses - Question #4Processes
An engineer received an alert of a zero-day vulnerability affecting desktop phones through which an attacker sends a crafted packet to a device, resets the credentials, makes the d...
zero-day vulnerabilityVoIPincident triagevulnerability management - Question #6Network Intrusion Analysis
An engineer receives an incident ticket with hundreds of intrusion alerts that require investigation. An analysis of the incident log shows that the alerts are from trusted IP addr...
IPS placementfalse positivesnetwork hardeningintrusion detection - Question #7Security Monitoring
A SOC team is informed that a UK-based user will be traveling between three countries over the next 60 days. Having the names of the 3 destination countries and the user's working...
VPN anomaly detectionbehavioral rulesSOC analysisuser behavior - Question #8Processes
An engineer receives a report that indicates a possible incident of a malicious insider sending company information to outside parties. What is the first action the engineer must t...
incident responseinsider threatprecursors and indicatorsIR process - Question #9Security Policies and Procedures
Refer to the exhibit. An engineer received a report that an attacker has compromised a workstation and gained access to sensitive customer data from the network using insecure prot...
network segmentationVLANinsecure protocolsfirewall policy - Question #10Techniques
How does Wireshark decrypt TLS network traffic?
WiresharkTLS decryptionkey log fileper-session secrets - Question #11Automation
Refer to the exhibit. An organization is using an internal application for printing documents that requires a separate registration on the website. The application allows format-fr...
Python regexinput validationusername policyautomation scripting - Question #12Automation
An engineer implemented a SOAR workflow to detect and respond to incorrect login attempts and anomalous user behavior. Since the implementation, the security team has received doze...
SOAR workflowfalse positivesconfirmation stepautomated remediation - Question #13Fundamentals
Refer to the exhibit. Where does it signify that a page will be stopped from loading when a scripting attack is detected?
HTTP security headersXSS protectionx-xss-protectionbrowser security - Question #14Fundamentals
What is the HTTP response code when the REST API information requested by the authenticated user cannot be found?
HTTP status codes404 not foundREST APIauthentication - Question #15Fundamentals
What is a principle of Infrastructure as Code?
Infrastructure as CodeIaC principlesautomationsystem management - Question #16Automation
Refer to the exhibit. An engineer configured this SOAR solution workflow to identify account theft threats and privilege escalation, evaluate risk, and respond by resolving the thr...
SOAR workflowendpoint snapshotthreat containmentforensic analysis - Question #17Fundamentals
An engineer is developing an application that requires frequent updates to close feedback loops and enable teams to quickly apply patches. The team wants their code updates to get...
CI/CDcontinuous deliverysoftware development lifecycleDevSecOps - Question #18Security Monitoring
Refer to the exhibit. An engineer notices a significant anomaly in the traffic in one of the host groups in Cisco Secure Network Analytics (Stealthwatch) and must analyze the top d...
Stealthwatchnetwork analyticstop conversationstraffic analysis - Question #19Host-Based Analysis
Employees report computer system crashes within the same week. An analyst is investigating one of the computers that crashed and discovers multiple shortcuts in the system's startu...
malware persistencestartup folderincident responseaffected systems - Question #20Automation
An engineer has created a bash script to automate a complicated process. During script execution, this error occurs: permission denied. Which command must be added to execute this...
bash scriptingchmodfile permissionsLinux commands - Question #21Techniques
An engineer is investigating several cases of increased incoming spam emails and suspicious emails from the HR and service departments. While checking the event sources, the websit...
phishingweb scrapingattack identificationspam analysis - Question #22Fundamentals
Refer to the exhibit. How are tokens authenticated when the REST API on a device is accessed from a REST API client?
REST APItoken authenticationAPI access control - Question #23Fundamentals
Refer to the exhibit. Where are the browser page rendering permissions displayed?
HTTP security headersx-frame-optionsbrowser renderingclickjacking protection - Question #24Techniques
An engineer is utilizing interactive behavior analysis to test malware in a sandbox environment to see how the malware performs when it is successfully executed. A location is secu...
malware analysisreverse engineeringdisassemblystatic analysis - Question #25Security Policies and Procedures
What is a limitation of cyber security risk insurance?
cyber insurancethird-party liabilityrisk managementpolicy limitations - Question #26Processes
An engineer returned to work and realized that payments that were received over the weekend were sent to the wrong recipient. The engineer discovered that the SaaS tool that proces...
incident responsebreach notificationSaaS securityescalation procedures - Question #27Network Intrusion Analysis
An analyst is alerted for a malicious file hash. After analysis, the analyst determined that an internal workstation is communicating over port 80 with an external server and that...
MITRE ATT&CKcommand and controlapplication layer protocolDuqu malware - Question #28Host-Based Analysis
A Mac laptop user notices that several files have disappeared from their laptop documents folder. While looking for the files, the user notices that the browser history was recentl...
macOS forensicssysdiagnosehost investigationdata exfiltration indicators - Question #29Techniques
A SOC analyst is investigating a recent email delivered to a high-value user for a customer whose network their organization monitors. The email includes a suspicious attachment ti...
malware sandboxindicators of compromiseunknown hashOSINT - Question #30Security Monitoring
A SOC analyst is notified by the network monitoring tool that there are unusual types of internal traffic on IP subnet 103.921.2239.0/24. The analyst discovers unexplained encrypte...
malware outbreaknetwork anomalyencrypted filessubnet monitoring - Question #31Network Intrusion Analysis
Refer to the exhibit. An employee is a victim of a social engineering phone call and installs remote access software to allow an "MS Support" technician to check his machine for ma...
data exfiltrationHTTPS traffic analysisbandwidth analysissocial engineering - Question #32Security Policies and Procedures
Refer to the exhibit. Which asset has the highest risk value?
risk assessmentasset valuationrisk prioritization - Question #33Security Policies and Procedures
What is the purpose of hardening systems?
system hardeningattack surface reductionsecure configuration - Question #34Security Policies and Procedures
A company launched an e-commerce website with multiple points of sale through internal and external e-stores. Customers access the stores from the public website, and employees acc...
PCI DSSdata encryptione-commerce compliancepersonal data protection - Question #35Security Policies and Procedures
An organization installed a new application server for IP phones. An automated process fetched user credentials from the Active Directory server, and the application will have acce...
data exfiltrationthreat prioritizationcredential exposurecloud security - Question #36Host-Based Analysis
A threat actor has crafted and sent a spear-phishing email with what appears to be a trustworthy link to the site of a conference that an employee recently attended. The employee c...
ransomwareC2 communicationendpoint securityspear-phishing kill chain - Question #37Security Monitoring
Refer to the exhibit. An engineer is investigating a case with suspicious usernames within the active directory. After the engineer investigates and cross-correlates events from ot...
Active Directorynetwork compromiseinsider threatevent correlation - Question #38Security Monitoring
Refer to the exhibit. For IP 192.168.1.209, what are the risk level, activity, and next step?
threat intelligencerisk level assessmentmalicious hostinvestigation workflow - Question #39Network Intrusion Analysis
Refer to the exhibit. What is the connection status of the ICMP event?
ICMPaccess policy rulesintrusion detectionfirewall policy - Question #40Techniques
An intruder attempted malicious activity and exchanged emails with a user and received corporate information, including email distribution lists. The intruder asked the user to eng...
social engineeringspear-phishingattack methodology - Question #41Techniques
Refer to the exhibit. A threat actor behind a single computer exploited a cloud-based application by sending multiple concurrent API requests. These requests made the application u...
API rate limitingDoS protectioncloud securityaccess control - Question #42Security Monitoring
A threat actor attacked an organization's Active Directory server from a remote location, and in a thirty-minute timeframe, stole the password for the administrator account and att...
Active DirectoryDLP triggerssecurity monitoringincident detection - Question #43Network Intrusion Analysis
Refer to the exhibit. A security analyst needs to investigate a security incident involving several suspicious connections with a possible attacker. Which tool should the analyst u...
packet sniffersource IP identificationnetwork forensicstool selection - Question #44Host-Based Analysis
Refer to the exhibit. Cisco Advanced Malware Protection installed on an end-user desktop has automatically submitted a low prevalence file to the Threat Grid analysis engine for fu...
Cisco AMPThreat Gridbehavioral indicatorsransomware analysis - Question #45Processes
The physical security department received a report that an unauthorized person followed an authorized individual to enter a secured premise. The incident was documented and given t...
physical securitytailgatingattacker movementincident analysis - Question #46Processes
A new malware variant is discovered hidden in pirated software that is distributed on the Internet. Executives have asked for an organizational risk assessment. The security office...
NIST risk assessmentvulnerability assessmentrisk calculationmalware analysis - Question #47Network Intrusion Analysis
Refer to the exhibit. At which stage of the threat kill chain is an attacker, based on these URIs of inbound web requests from known malicious Internet scanners?
kill chainreconnaissanceweb scanningthreat intelligence - Question #48Techniques
What should a security analyst consider when comparing inline traffic interrogation with traffic tapping to determine which approach to use in the network?
traffic tappinginline interrogationnetwork monitoringtraffic analysis - Question #49Techniques
Refer to the exhibit. Which two steps mitigate attacks on the webserver from the Internet? (Choose two.)
ACLTLSDMZproxy server - Question #50Security Policies and Procedures
According to GDPR, what should be done with data to ensure its confidentiality, integrity, and availability?
GDPRdata protection impact assessmentdata privacycompliance - Question #51Processes
A payroll administrator noticed unexpected changes within a piece of software and reported the incident to the incident response team. Which actions should be taken at this step in...
incident responseevidence handlingchain of custodysoftware integrity