[Sep 15, 2023] Pass CyberOps Professional 350-201 Exam With 141 Questions
Ultimate Guide to Prepare Free Cisco 350-201 Exam Questions and Answer
Cisco 350-201 certification exam is designed to test the skills and knowledge of cybersecurity professionals in using Cisco security technologies to perform cyber operations. 350-201 exam is intended for those who want to validate their expertise in implementing and managing security solutions using Cisco tools and technologies.
NEW QUESTION # 11
After a recent malware incident, the forensic investigator is gathering details to identify the breach and causes. The investigator has isolated the affected workstation. What is the next step that should be taken in this investigation?
- A. Compare workstation configuration and asset configuration policy to identify gaps.
- B. Inspect registry entries for recently executed files.
- C. Review audit logs for privilege escalation events.
- D. Analyze the applications and services running on the affected workstation.
Answer: B
NEW QUESTION # 12 
Refer to the exhibit. IDS is producing an increased amount of false positive events about brute force attempts on the organization's mail server. How should the Snort rule be modified to improve performance?
- A. Tune the count and seconds threshold of the rule
- B. Change the rule content match to case sensitive
- C. Set the rule to track the source IP
- D. Block list of internal IPs from the rule
Answer: B
NEW QUESTION # 13
A security manager received an email from an anomaly detection service, that one of their contractors has downloaded 50 documents from the company's confidential document management folder using a company- owned asset al039-ice-4ce687TL0500. A security manager reviewed the content of downloaded documents and noticed that the data affected is from different departments. What are the actions a security manager should take?
- A. Communicate with the contractor to identify the motives.
- B. Escalate to contractor's manager.
- C. Report to the incident response team.
- D. Measure confidentiality level of downloaded documents.
Answer: C
NEW QUESTION # 14
Employees receive an email from an executive within the organization that summarizes a recent security breach and requests that employees verify their credentials through a provided link. Several employees report the email as suspicious, and a security analyst is investigating the reports. Which two steps should the analyst take to begin this investigation? (Choose two.)
- A. Evaluate the intrusion detection system alerts to determine the threat source and attack surface.
- B. Examine the firewall and HIPS configuration to identify the exploited vulnerabilities and apply recommended mitigation.
- C. Check the email header to identify the sender and analyze the link in an isolated environment.
- D. Communicate with employees to determine who opened the link and isolate the affected assets.
- E. Review the mail server and proxy logs to identify the impact of a potential breach.
Answer: B,C
Explanation:
Section: (none)
Explanation
NEW QUESTION # 15
A SOC team is investigating a recent, targeted social engineering attack on multiple employees. Cross- correlated log analysis revealed that two hours before the attack, multiple assets received requests on TCP port 79. Which action should be taken by the SOC team to mitigate this attack?
- A. Configure affected devices to disable the Finger service.
- B. Disable affected assets and isolate them for further investigation.
- C. Configure affected devices to disable NETRJS protocol.
- D. Disable BIND forwarding from the DNS server to avoid reconnaissance.
Answer: A
NEW QUESTION # 16
Drag and drop the threat from the left onto the scenario that introduces the threat on the right. Not all options are used.
Answer:
Explanation:
NEW QUESTION # 17
Drag and drop the NIST incident response process steps from the left onto the actions that occur in the steps on the right.
Answer:
Explanation:
Reference:
https://www.securitymetrics.com/blog/6-phases-incident-response-plan
NEW QUESTION # 18
Drag and drop the phases to evaluate the security posture of an asset from the left onto the activity that happens during the phases on the right.
Answer:
Explanation:
NEW QUESTION # 19
A security engineer discovers that a spreadsheet containing confidential information for nine of their employees was fraudulently posted on a competitor's website. The spreadsheet contains names, salaries, and social security numbers. What is the next step the engineer should take in this investigation?
- A. Engage the legal department to explore action against the competitor that posted the spreadsheet.
- B. Check incoming and outgoing communications to identify spoofed emails.
- C. Determine if there is internal knowledge of this incident.
- D. Disconnect the network from Internet access to stop the phishing threats and regain control.
Answer: A
NEW QUESTION # 20
An engineer is developing an application that requires frequent updates to close feedback loops and enable teams to quickly apply patches. The team wants their code updates to get to market as often as possible. Which software development approach should be used to accomplish these goals?
- A. continuous delivery
- B. continuous deployment
- C. continuous integration
- D. continuous monitoring
Answer: A
NEW QUESTION # 21
An engineer notices that unauthorized software was installed on the network and discovers that it was installed by a dormant user account. The engineer suspects an escalation of privilege attack and responds to the incident. Drag and drop the activities from the left into the order for the response on the right.
Answer:
Explanation:
NEW QUESTION # 22
A malware outbreak is detected by the SIEM and is confirmed as a true positive. The incident response team follows the playbook to mitigate the threat. What is the first action for the incident response team?
- A. Patch detected vulnerabilities from critical hosts
- B. Isolate critical hosts from the network
- C. Perform analysis based on the established risk factors
- D. Assess the network for unexpected behavior
Answer: B
NEW QUESTION # 23
Which bash command will print all lines from the "colors.txt" file containing the non case-sensitive pattern "Yellow"?
- A. grep "Yellow" colors.txt
- B. locate -i "Yellow" colors.txt
- C. grep -i "yellow" colors.txt
- D. locate "yellow" colors.txt
Answer: C
NEW QUESTION # 24
Refer to the exhibit.
What results from this script?
- A. A search is conducted for additional seeds
- B. Domains are compared to seed rules
- C. Seeds for existing domains are checked
- D. A list of domains as seeds is blocked
Answer: A
NEW QUESTION # 25
Refer to the exhibit.
What is occurring in this packet capture?
- A. TCP port scan
- B. TCP flood
- C. DNS tunneling
- D. DNS flood
Answer: B
NEW QUESTION # 26
An organization had an incident with the network availability during which devices unexpectedly malfunctioned. An engineer is investigating the incident and found that the memory pool buffer usage reached a peak before the malfunction. Which action should the engineer take to prevent this issue from reoccurring?
- A. Enable memory threshold notifications.
- B. Disable CPU threshold trap toward the SNMP server.
- C. Enable memory tracing notifications.
- D. Disable memory limit.
Answer: A
NEW QUESTION # 27
An organization is using a PKI management server and a SOAR platform to manage the certificate lifecycle. The SOAR platform queries a certificate management tool to check all endpoints for SSL certificates that have either expired or are nearing expiration. Engineers are struggling to manage problematic certificates outside of PKI management since deploying certificates and tracking them requires searching server owners manually. Which action will improve workflow automation?
- A. Integrate a SOAR solution with Active Directory to pull server owner details from the AD and send an automated email for problematic certificates requesting updates.
- B. Implement a new workflow within SOAR to create tickets in the incident response system, assign problematic certificate update requests to server owners, and register change requests.
- C. Integrate a PKI solution within SOAR to create certificates within the SOAR engines to track, update, and monitor problematic certificates.
- D. Implement a new workflow for SOAR to fetch a report of assets that are outside of the PKI zone, sort assets by certification management leads and automate alerts that updates are needed.
Answer: D
NEW QUESTION # 28
The incident response team receives information about the abnormal behavior of a host. A malicious file is found being executed from an external USB flash drive. The team collects and documents all the necessary evidence from the computing resource. What is the next step?
- A. Isolate the infected host from the rest of the subnet
- B. Install malware prevention software on the host
- C. Conduct a risk assessment of systems and applications
- D. Analyze network traffic on the host's subnet
Answer: A
NEW QUESTION # 29
An organization suffered a security breach in which the attacker exploited a Netlogon Remote Protocol vulnerability for further privilege escalation. Which two actions should the incident response team take to prevent this type of attack from reoccurring? (Choose two.)
- A. Implement a patch management process.
- B. Automate antivirus scans of the company servers.
- C. Define roles and responsibilities in the incident response playbook.
- D. Apply existing patches to the company servers.
- E. Scan the company server files for known viruses.
Answer: B,C
NEW QUESTION # 30
An engineer notices that unauthorized software was installed on the network and discovers that it was installed by a dormant user account. The engineer suspects an escalation of privilege attack and responds to the incident. Drag and drop the activities from the left into the order for the response on the right.
Answer:
Explanation:
NEW QUESTION # 31
Refer to the exhibit.
Which command was executed in PowerShell to generate this log?
- A. Get-EventLog -LogName*
- B. Get-EventLog -List
- C. Get-WinEvent -ListLog* -ComputerName localhost
- D. Get-WinEvent -ListLog*
Answer: A
NEW QUESTION # 32
......
Pass 350-201 Tests Engine pdf - All Free Dumps: https://prep4tests.pass4sures.top/CyberOps-Professional/350-201-testking-braindumps.html