350-201 Practice Questions
128 real 350-201 exam questions with expert-verified answers and explanations. Page 2 of 3.
- Question #52Processes
A company recently completed an internal audit and discovered that there is CSRF vulnerability in 20 of its hosted applications. Based on the audit, which recommendation should an...
CSRFvulnerability managementrisk scoringpatch prioritization - Question #53Network Intrusion Analysis
An engineer is analyzing a possible compromise that happened a week ago when the company database servers unexpectedly went down. The analysis reveals that attackers tampered with...
DDoS mitigationMSSQLIPSfirewall - Question #54Security Policies and Procedures
A European-based advertisement company collects tracking information from partner websites and stores it on a local server to provide tailored ads. Which standard must the company...
GDPRdata privacyEuropean compliancedata protection - Question #55Processes
An organization had a breach due to a phishing attack. An engineer leads a team through the recovery phase of the incident response process. Which action should be taken during thi...
incident recoveryIDS/IPS signaturesphishinghost reimaging - Question #56Processes
An engineer is going through vulnerability triage with company management because of a recent malware outbreak from which 21 affected assets need to be patched or remediated. Manag...
vulnerability managementrisk acceptancedocumentationrisk triage - Question #57Host-Based Analysis
A security engineer deploys an enterprise-wide host/endpoint technology for all of the company's corporate PCs. Management requests the engineer to block a selected set of applicat...
application whitelistingendpoint securityapplication controlhost security - Question #58Fundamentals
Which command does an engineer use to set read/write/execute access on a folder for everyone who reaches the resource?
Linux permissionschmodfile access controlUnix commands - Question #59Processes
A SIEM tool fires an alert about a VPN connection attempt from an unusual location. The incident response team validates that an attacker has installed a remote access tool on a us...
VPN anomalyincident responsecredential compromiseremote access - Question #60Processes
A threat actor used a phishing email to deliver a file with an embedded macro. The file was opened, and a remote code execution attack occurred in a company's infrastructure. Which...
incident recoveryphishingremote code executionpatch deployment - Question #61Processes
A patient views information that is not theirs when they sign in to the hospital's online portal. The patient calls the support center at the hospital but continues to be put on ho...
incident responsePII protectioncontainmentdata breach - Question #62Automation
Refer to the exhibit. What results from this script?
domain analysisDGA detectionseed generationscripting - Question #63Host-Based Analysis
Refer to the exhibit. An engineer is reverse engineering a suspicious file by examining its resources. What does this file indicate?
file format identificationstatic analysisPE formatreverse engineering - Question #64Host-Based Analysis
Refer to the exhibit. An engineer is performing a static analysis on a malware and knows that it is capturing keys and webcam events on a company server. What is the indicator of c...
static malware analysisIOCobfuscationkeylogger - Question #65Security Policies and Procedures
An audit is assessing a small business that is selling automotive parts and diagnostic services. Due to increased customer demands, the company recently started to accept credit ca...
PCI DSScompliancepayment card industryPOS security - Question #66Network Intrusion Analysis
A customer is using a central device to manage network devices over SNMPv2. A remote attacker caused a denial of service condition and can trigger this vulnerability by issuing a G...
SNMPv2denial of serviceSNMP securitynetwork vulnerability - Question #67Security Monitoring
Refer to the exhibit. Which indicator of compromise is represented by this STIX?
STIXthreat intelligenceIOCmalware hosting - Question #68Network Intrusion Analysis
Refer to the exhibit. What is occurring in this packet capture?
TCP floodpacket analysisDDoSnetwork traffic analysis - Question #69Processes
Refer to the exhibit. How must these advisories be prioritized for handling?
vulnerability prioritizationCVSS scoringrisk assessmentpatch management - Question #70Processes
The incident response team receives information about the abnormal behavior of a host. A malicious file is found being executed from an external USB flash drive. The team collects...
incident responsecontainmentmalwareUSB threat - Question #71Security Monitoring
An organization had several cyberattacks over the last 6 months and has tasked an engineer with looking for patterns or trends that will help the organization anticipate future att...
predictive analyticsthreat intelligencedata analyticsattack patterns - Question #72Processes
A malware outbreak is detected by the SIEM and is confirmed as a true positive. The incident response team follows the playbook to mitigate the threat. What is the first action for...
incident responsecontainmentmalware outbreakSIEM - Question #73Security Monitoring
Refer to the exhibit. Cisco Advanced Malware Protection installed on an end-user desktop automatically submitted a low prevalence file to the Threat Grid analysis engine. What shou...
Cisco AMPThreat Gridmalware analysisthreat scoring - Question #74Automation
An organization is using a PKI management server and a SOAR platform to manage the certificate lifecycle. The SOAR platform queries a certificate management tool to check all endpo...
SOARcertificate managementPKIworkflow automation - Question #75Fundamentals
Refer to the exhibit. Which data format is being used?
XMLdata formatsstructured data - Question #76Processes
The incident response team was notified of detected malware. The team identified the infected hosts, removed the malware, restored the functionality and data of infected systems, a...
NIST incident handlingcontainmentIR proceduresincident lifecycle - Question #77Host-Based Analysis
An employee abused PowerShell commands and script interpreters, which lead to an indicator of compromise (IOC) trigger. The IOC event shows that a known malicious file has been exe...
IOCPowerShell abusemalware executionendpoint detection - Question #78Host-Based Analysis
Refer to the exhibit. Which command was executed in PowerShell to generate this log?
PowerShellWindows Event LogGet-EventLoglog analysis - Question #79Security Monitoring
Refer to the exhibit. Cisco Rapid Threat Containment using Cisco Secure Network Analytics (Stealthwatch) and ISE detects the threat of malware-infected 802.1x authenticated endpoin...
Cisco StealthwatchISEnetwork telemetrythreat containment - Question #80Techniques
A security architect is working in a processing center and must implement a DLP solution to detect and prevent any type of copy and paste attempts of sensitive data within unapprov...
DLPdata in useendpoint securitydata protection - Question #81Processes
A security analyst receives an escalation regarding an unidentified connection on the Accounting A1 server within a monitored zone. The analyst pulls the logs and discovers that a...
incident responseforensic analysisPowerShellWMI - Question #82Processes
A security expert is investigating a breach that resulted in a $32 million loss from customer accounts. Hackers were able to steal API keys and two-factor codes due to a vulnerabil...
SecDevOpsSDLC securityvulnerability detectionAPI security - Question #83Techniques
An API developer is improving an application code to prevent DDoS attacks. The solution needs to accommodate instances of a large number of API requests coming for legitimate purpo...
DDoS mitigationrate limitingAPI securityREST API - Question #84Network Intrusion Analysis
Refer to the exhibit. IDS is producing an increased amount of false positive events about brute force attempts on the organization's mail server. How should the Snort rule be modif...
Snort rulesIDS tuningfalse positivesthreshold configuration - Question #85Security Monitoring
Where do threat intelligence tools search for data to identify potential malicious IP addresses, domain names, and URLs?
threat intelligencethreat feedsmalicious IPsURLs - Question #86Network Intrusion Analysis
An engineer wants to review the packet overviews of SNORT alerts. When printing the SNORT alerts, all the packet headers are included, and the file is too large to utilize. Which a...
Snort output modulesalert configurationpacket overviewIDS - Question #87Security Policies and Procedures
A company's web server availability was breached by a DDoS attack and was offline for 3 hours because it was not deemed a critical asset in the incident response playbook. Leadersh...
risk assessmentrisk calculationlikelihoodthreat events - Question #88Security Monitoring
An employee who often travels abroad logs in from a first-seen country during non-working hours. The SIEM tool generates an alert that the user is forwarding an increased amount of...
UEBAbehavioral analyticsanomaly detectioninsider threat - Question #89Security Monitoring
How is a SIEM tool used?
SIEMlog analysissecurity alertsnetwork monitoring - Question #90Network Intrusion Analysis
Refer to the exhibit. What is the threat in this Wireshark traffic capture?
SYN floodDDoSWireshark analysisTCP traffic - Question #91Automation
An engineer is moving data from NAS servers in different departments to a combined storage database so that the data can be accessed and analyzed by the organization on-demand. Whi...
data ingestiondata managementNASstorage consolidation - Question #92Security Policies and Procedures
What is a benefit of key risk indicators?
key risk indicatorsrisk posturerisk managementmetrics - Question #106Security Policies and Procedures
An analyst wants to upload an infected file containing sensitive information to a hybrid-analysis sandbox. According to the NIST.SP 800-150 guide to cyber threat information sharin...
NIST SP 800-150threat intelligence sharingPII removalsandbox analysis - Question #107Host-Based Analysis
Refer to the exhibit. An engineer received multiple reports from employees unable to log into systems with the error: The Group Policy Client service failed to logon ?Access is den...
elevation of privilegesGroup Policyunauthorized system modificationsbreach classification - Question #108Security Policies and Procedures
What is needed to assess risk mitigation effectiveness in an organization?
risk mitigationcontrol effectivenesscost-benefit analysisKPI - Question #109Security Monitoring
Refer to the exhibit. Where is the MIME type that should be followed indicated?
HTTP security headersMIME sniffingx-content-type-optionscontent security - Question #110Techniques
Refer to the exhibit. Based on the detected vulnerabilities, what is the next recommended mitigation step?
CVSS scoringvulnerability prioritizationpatch managementremediation - Question #111Processes
An engineer received an incident ticket of a malware outbreak and used antivirus and malware removal tools to eradicate the threat. The engineer notices that abnormal processes are...
malware eradicationincident playbookcontainmenthost remediation - Question #112Techniques
The SIEM tool informs a SOC team of a suspicious file. The team initializes the analysis with an automated sandbox tool, sets up a controlled laboratory to examine the malware spec...
malware analysisstatic analysisdynamic analysisbehavioral analysis - Question #113Network Intrusion Analysis
A logistic company must use an outdated application located in a private VLAN during the migration to new technologies. The IPS blocked and reported an unencrypted communication. W...
IPS tuningallowlistlegacy applicationfalse positive reduction - Question #114Security Policies and Procedures
A company recently started accepting credit card payments in their local warehouses and is undergoing a PCI audit. Based on business requirements, the company needs to store sensit...
PCI DSSsensitive authentication datadata storage compliancecard data