260 Exam Questions for 200-201 Updated Versions With Test Engine
Pass 200-201 Exam with Updated 200-201 Exam Dumps PDF 2024
NEW QUESTION # 84
Which type of evidence supports a theory or an assumption that results from initial evidence?
- A. corroborative
- B. best
- C. indirect
- D. probabilistic
Answer: A
Explanation:
Explanation
NEW QUESTION # 85
What is an example of social engineering attacks?
- A. receiving an email from human resources requesting a visit to their secure website to update contact information
- B. receiving an unexpected email from an unknown person with an uncharacteristic attachment from someone in the same company
- C. receiving an invitation to the department's weekly WebEx meeting
- D. sending a verbal request to an administrator who knows how to change an account password
Answer: A
NEW QUESTION # 86
An engineer needs to discover alive hosts within the 192.168.1.0/24 range without triggering intrusive portscan alerts on the IDS device using Nmap. Which command will accomplish this goal?
- A. nmap -sP 192.168.1.0/24
- B. nmap -sV 192.168.1.0/24
- C. nmap -sL 192.168.1.0/24
- D. nmap --top-ports 192.168.1.0/24
Answer: C
NEW QUESTION # 87
What is an example of social engineering attacks?
- A. receiving an email from human resources requesting a visit to their secure website to update contact information
- B. receiving an invitation to the department's weekly WebEx meeting
- C. sending a verbal request to an administrator who knows how to change an account password
- D. receiving an unexpected email from an unknown person with an attachment from someone in the same company
Answer: C
NEW QUESTION # 88
DRAG DROP
Drag and drop the access control models from the left onto the correct descriptions on the right.
Select and Place:
Answer:
Explanation:
NEW QUESTION # 89
A security specialist notices 100 HTTP GET and POST requests for multiple pages on the web servers. The agent in the requests contains PHP code that, if executed, creates and writes to a new PHP file on the webserver. Which event category is described?
- A. reconnaissance
- B. exploitation
- C. action on objectives
- D. installation
Answer: D
Explanation:
Section: Security Concepts
NEW QUESTION # 90
Refer to the exhibit.
What is shown in this PCAP file?
- A. The User-Agent is Mozilla/5.0.
- B. Timestamps are indicated with error.
- C. The HTTP GET is encoded.
- D. The protocol is TCP.
Answer: C
NEW QUESTION # 91
What is the difference between mandatory access control (MAC) and discretionary access control (DAC)?
- A. MAC is the strictest of all levels of control and DAC is object-based access
- B. MAC is controlled by the discretion of the owner and DAC is controlled by an administrator
- C. DAC is controlled by the operating system and MAC is controlled by an administrator
- D. DAC is the strictest of all levels of control and MAC is object-based access
Answer: A
NEW QUESTION # 92 
Refer to the exhibit. What information is depicted?
- A. NetFlow data
- B. IPS event data
- C. network discovery event
- D. IIS data
Answer: A
NEW QUESTION # 93
What is rule-based detection when compared to statistical detection?
- A. proof of a user's identity
- B. likelihood of user's action
- C. falsification of a user's identity
- D. proof of a user's action
Answer: D
NEW QUESTION # 94
Refer to the exhibit.
An engineer is analyzing this Cuckoo Sandbox report for a PDF file that has been downloaded from an email. What is the state of this file?
- A. The file has an embedded Windows 32 executable and the Yara field lists suspicious features for further analysis.
- B. The file has an embedded executable and was matched by PEiD threat signatures for further analysis.
- C. The file was matched by PEiD threat signatures but no suspicious features are identified since the signature list is up to date.
- D. The file has an embedded non-Windows executable but no suspicious features are identified.
Answer: A
NEW QUESTION # 95
Which two elements are assets in the role of attribution in an investigation? (Choose two.)
- A. laptop
- B. context
- C. threat actor
- D. session
- E. firewall logs
Answer: B,C
NEW QUESTION # 96
While viewing packet capture data, an analyst sees that one IP is sending and receiving traffic for multiple devices by modifying the IP header.
Which technology makes this behavior possible?
- A. TOR
- B. encapsulation
- C. NAT
- D. tunneling
Answer: C
NEW QUESTION # 97
An investigator is examining a copy of an ISO file that is stored in CDFS format. What type of evidence is this file?
- A. data from a CD copied using Linux system
- B. data from a DVD copied using Windows system
- C. data from a CD copied using Windows
- D. data from a CD copied using Mac-based system
Answer: A
NEW QUESTION # 98
An analyst is exploring the functionality of different operating systems.
What is a feature of Windows Management Instrumentation that must be considered when deciding on an operating system?
- A. has a Common Information Model, which describes installed hardware and software
- B. queries Linux devices that have Microsoft Services for Linux installed
- C. is an efficient tool for working with Active Directory
- D. deploys Windows Operating Systems in an automated fashion
Answer: A
NEW QUESTION # 99
Which system monitors local system operation and local network access for violations of a security policy?
- A. host-based intrusion detection
- B. host-based firewall
- C. antivirus
- D. systems-based sandboxing
Answer: B
Explanation:
Section: Host-Based Analysis
NEW QUESTION # 100
A user received a malicious attachment but did not run it.
Which category classifies the intrusion?
- A. reconnaissance
- B. delivery
- C. weaponization
- D. installation
Answer: B
NEW QUESTION # 101
Which HTTP header field is used in forensics to identify the type of browser used?
- A. accept-language
- B. host
- C. user-agent
- D. referrer
Answer: C
Explanation:
Explanation
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:12.0) Gecko/20100101 Firefox/12.0 In computing, a user agent is any software, acting on behalf of a user, which "retrieves, renders and facilitates end-user interaction with Web content".[1] A user agent is therefore a special kind of software agent.
https://en.wikipedia.org/wiki/User_agent#User_agent_identification
A user agent is a computer program representing a person, for example, a browser in a Web context.
https://developer.mozilla.org/en-US/docs/Glossary/User_agent
NEW QUESTION # 102
Refer to the exhibit.
What is the potential threat identified in this Stealthwatch dashboard?
- A. Host 10.201.3.149 is sending data to 152.46.6.91 using TCP/443.
- B. Traffic to 152.46.6.149 is being denied by an Advanced Network Control policy.
- C. Host 152.46.6.91 is being identified as a watchlist country for data transfer.
- D. Host 10.201.3.149 is receiving almost 19 times more data than is being sent to host 152.46.6.91.
Answer: D
NEW QUESTION # 103
......
200-201 Exam Dumps - Free Demo & 365 Day Updates: https://pdfpractice.actual4dumps.com/200-201-study-material.html