[Dec-2024] 350-201 Questions - Truly Beneficial For Your Cisco Exam
Download Cisco 350-201 Sample Questions
Cisco 350-201 exam is a challenging test that requires a thorough understanding of cybersecurity and Cisco security technologies. It is an excellent certification for security professionals who want to enhance their knowledge and validate their skills in the field of cybersecurity.
Cisco 350-201 (Performing CyberOps Using Cisco Security Technologies) certification exam is designed for IT professionals who are interested in pursuing a career in cybersecurity. 350-201 exam tests the candidate's knowledge and skills in various aspects of cybersecurity, including threat intelligence, network security, endpoint protection, and cloud security. Candidates who pass the exam will have demonstrated their ability to use Cisco security technologies to detect, prevent, and respond to cybersecurity threats effectively.
NEW QUESTION # 49
An audit is assessing a small business that is selling automotive parts and diagnostic services. Due to increased customer demands, the company recently started to accept credit card payments and acquired a POS terminal.
Which compliance regulations must the audit apply to the company?
- A. HIPAA
- B. COBIT
- C. PCI DSS
- D. FISMA
Answer: C
Explanation:
The Payment Card Industry Data Security Standard (PCI DSS) is the compliance regulation that must be applied to a company that accepts credit card payments. PCI DSS is a set of security standards designed to ensure that all companies that accept, process, store, or transmit credit card information maintain a secure environment. Since the small business in question has acquired a POS terminal to handle credit card transactions, it falls under the purview of PCI DSS compliance.
NEW QUESTION # 50
Refer to the exhibit.
An engineer configured this SOAR solution workflow to identify account theft threats and privilege escalation, evaluate risk, and respond by resolving the threat. This solution is handling more threats than Security analysts have time to analyze. Without this analysis, the team cannot be proactive and anticipate attacks. Which action will accomplish this goal?
- A. Exclude the step "Check for GeoIP location" to allow analysts to analyze the location and the associated risk based on asset criticality
- B. Include a step "Take a Snapshot" to capture the endpoint state to contain the threat for analysis
- C. Exclude the step "BAN malicious IP" to allow analysts to conduct and track the remediation
- D. Include a step "Reporting" to alert the security department of threats identified by the SOAR reporting engine
Answer: C
NEW QUESTION # 51
Refer to the exhibit.
Where is the MIME type that should be followed indicated?
- A. x-xss-protection
- B. x-test-debug
- C. strict-transport-security
- D. x-content-type-options
Answer: B
NEW QUESTION # 52
An organization had a breach due to a phishing attack. An engineer leads a team through the recovery phase of the incident response process. Which action should be taken during this phase?
- A. Host a discovery meeting and define configuration and policy updates
- B. Identify the traffic with data capture using Wireshark and review email filters
- C. Update the IDS/IPS signatures and reimage the affected hosts
- D. Identify the systems that have been affected and tools used to detect the attack
Answer: C
Explanation:
During the recovery phase of the incident response process, especially after a phishing attack, it's crucial to update the Intrusion Detection System (IDS) and Intrusion Prevention System (IPS) signatures to detect and prevent similar attacks in the future. Additionally, reimaging the affected hosts ensures that any malware or changes made by the attacker are removed and that the systems are restored to a known good state. This step is essential to eradicate the threat and restore normal operations
NEW QUESTION # 53
Refer to the exhibit.
Which command was executed in PowerShell to generate this log?
- A. Get-WinEvent -ListLog*
- B. Get-EventLog -LogName*
- C. Get-WinEvent -ListLog* -ComputerName localhost
- D. Get-EventLog -List
Answer: B
NEW QUESTION # 54
An engineer implemented a SOAR workflow to detect and respond to incorrect login attempts and anomalous user behavior. Since the implementation, the security team has received dozens of false positive alerts and negative feedback from system administrators and privileged users. Several legitimate users were tagged as a threat and their accounts blocked, or credentials reset because of unexpected login times and incorrectly typed credentials. How should the workflow be improved to resolve these issues?
- A. Add a confirmation step through which SOAR informs the affected user and asks them to confirm whether they made the attempts
- B. Change the SOAR configuration flow to remove the automatic remediation that is increasing the false positives and triggering threats
- C. Increase incorrect login tries and tune anomalous user behavior not to affect privileged accounts
- D. Meet with privileged users to increase awareness and modify the rules for threat tags and anomalous behavior alerts
Answer: A
Explanation:
Implementing a confirmation step in the SOAR (Security Orchestration, Automation, and Response) workflow can significantly reduce false positives and improve the accuracy of threat detection. By adding a mechanism that informs the affected user of the detected activity and asks for their confirmation, the system can distinguish between legitimate and malicious actions more effectively. This approach respects the user's context and behavior patterns, allowing for a more nuanced response to security alerts. It also reduces the inconvenience caused to legitimate users by avoiding unnecessary account blocks or credential resets.
The other options, while potentially useful in certain contexts, do not address the immediate issue of distinguishing between false positives and actual threats as effectively as a confirmation step does. Meeting with privileged users (option A) and increasing incorrect login tries (option D) may help to some extent but do not provide an immediate verification mechanism. Changing the SOAR configuration flow (option B) could reduce automatic remediation, but it might also reduce the system's ability to respond to actual threats promptly.
Therefore, adding a confirmation step is the most direct and effective way to improve the workflow and resolve the issues described. It enhances the precision of the SOAR system and maintains a balance between security and user convenience.
NEW QUESTION # 55
How is a SIEM tool used?
- A. To collect security data from authentication failures and cyber attacks and forward it for analysis
- B. To search and compare security data against acceptance standards and generate reports for analysis
- C. To compare security alerts against configured scenarios and trigger system responses
- D. To collect and analyze security data from network devices and servers and produce alerts
Answer: D
Explanation:
Explanation/Reference: https://www.varonis.com/blog/what-is-siem/
NEW QUESTION # 56
An engineer implemented a SOAR workflow to detect and respond to incorrect login attempts and anomalous user behavior. Since the implementation, the security team has received dozens of false positive alerts and negative feedback from system administrators and privileged users. Several legitimate users were tagged as a threat and their accounts blocked, or credentials reset because of unexpected login times and incorrectly typed credentials. How should the workflow be improved to resolve these issues?
- A. Increase incorrect login tries and tune anomalous user behavior not to affect privileged accounts
- B. Meet with privileged users to increase awareness and modify the rules for threat tags and anomalous behavior alerts
- C. Change the SOAR configuration flow to remove the automatic remediation that is increasing the false positives and triggering threats
- D. Add a confirmation step through which SOAR informs the affected user and asks them to confirm whether they made the attempts
Answer: C
NEW QUESTION # 57
An engineer is analyzing a possible compromise that happened a week ago when the company ? (Choose two.)
- A. SHA512
- B. Wireshark
- C. autopsy
- D. IPS
- E. firewall
Answer: B,E
NEW QUESTION # 58
Refer to the exhibit.
The Cisco Secure Network Analytics (Stealthwatch) console alerted with "New Malware Server Discovered" and the IOC indicates communication from an end-user desktop to a Zeus C&C Server. Drag and drop the actions that the analyst should take from the left into the order on the right to investigate and remediate this IOC.
Answer:
Explanation:
NEW QUESTION # 59
An organization lost connectivity to critical servers, and users cannot access business applications and internal websites. An engineer checks the network devices to investigate the outage and determines that all devices are functioning. Drag and drop the steps from the left into the sequence on the right to continue investigating this issue. Not all options are used.
Answer:
Explanation:
NEW QUESTION # 60
Which command does an engineer use to set read/write/execute access on a folder for everyone who reaches the resource?
- A. chmod 777
- B. chmod 774
- C. chmod 775
- D. chmod 666
Answer: A
Explanation:
Explanation/Reference: https://www.pluralsight.com/blog/it-ops/linux-file-permissions
NEW QUESTION # 61
An organization installed a new application server for IP phones. An automated process fetched user credentials from the Active Directory server, and the application will have access to on-premises and cloud services. Which security threat should be mitigated first?
- A. aligning access control policies
- B. exfiltration during data transfer
- C. attack using default accounts
- D. data exposure from backups
Answer: C
Explanation:
The first security threat that should be mitigated when installing a new application server for IP phones is the attack using default accounts. Default accounts often have preset usernames and passwords that are widely known and can be easily exploited by attackers. It is crucial to change these default credentials to prevent unauthorized access
NEW QUESTION # 62
An engineer wants to review the packet overviews of SNORT alerts. When printing the SNORT alerts, all the packet headers are included, and the file is too large to utilize. Which action is needed to correct this problem?
- A. Modify the output module rule to "output alert_fast: output filename"
- B. Modify the alert rule to "output alert_syslog: output log"
- C. Modify the output module rule to "output alert_quick: output filename"
- D. Modify the alert rule to "output alert_syslog: output header"
Answer: B
Explanation:
Reference:
%2F20201231%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20201231T141156Z&X-Amz- Expires=172800&X-Amz-SignedHeaders=host&X-Amz- Signature=e122ab6eb1659e13b3bc6bb2451ce693c0298b76c1962c3743924bc5fd83d382
NEW QUESTION # 63
An employee abused PowerShell commands and script interpreters, which lead to an indicator of compromise (IOC) trigger. The IOC event shows that a known malicious file has been executed, and there is an increased likelihood of a breach. Which indicator generated this IOC event?
- A. ExecutedMalware.ioc
- B. Crossrider.ioc
- C. ConnectToSuspiciousDomain.ioc
- D. W32 AccesschkUtility.ioc
Answer: A
Explanation:
The indicator of compromise (IOC) event triggered by the abuse of PowerShell commands and script interpreters, leading to the execution of a known malicious file, is most likely generated by an ExecutedMalware.ioc. This type of IOC is specifically designed to detect the execution of malicious software on a system, which aligns with the scenario described4.
NEW QUESTION # 64
What is needed to assess risk mitigation effectiveness in an organization?
- A. updated list of vulnerable systems
- B. analysis of key performance indicators
- C. cost-effectiveness of control measures
- D. compliance with security standards
Answer: B
NEW QUESTION # 65
A security manager received an email from an anomaly detection service, that one of their contractors has downloaded 50 documents from the company's confidential document management folder using a company- owned asset al039-ice-4ce687TL0500. A security manager reviewed the content of downloaded documents and noticed that the data affected is from different departments. What are the actions a security manager should take?
- A. Report to the incident response team.
- B. Measure confidentiality level of downloaded documents.
- C. Escalate to contractor's manager.
- D. Communicate with the contractor to identify the motives.
Answer: A
NEW QUESTION # 66 
Refer to the exhibit. Cisco Advanced Malware Protection installed on an end-user desktop has automatically submitted a low prevalence file to the Threat Grid analysis engine for further analysis. What should be concluded from this report?
- A. The prioritized behavioral indicators of compromise do not justify the execution of the "ransomware" because the scores do not indicate the likelihood of malicious ransomware.
- B. The prioritized behavioral indicators of compromise do not justify the execution of the "ransomware" because the scores are high and do not indicate the likelihood of malicious ransomware.
- C. The prioritized behavioral indicators of compromise justify the execution of the "ransomware" because the scores are low and indicate the likelihood that malicious ransomware has been detected.
- D. The prioritized behavioral indicators of compromise justify the execution of the "ransomware" because the scores are high and indicate the likelihood that malicious ransomware has been detected.
Answer: D
NEW QUESTION # 67
Refer to the exhibit.
A security analyst needs to investigate a security incident involving several suspicious connections with a possible attacker. Which tool should the analyst use to identify the source IP of the offender?
- A. packet sniffer
- B. firewall manager
- C. SIEM
- D. malware analysis
Answer: A
NEW QUESTION # 68
The incident response team was notified of detected malware. The team identified the infected hosts, removed the malware, restored the functionality and data of infected systems, and planned a company meeting to improve the incident handling capability. Which step was missed according to the NIST incident handling guide?
- A. Contain the malware
- B. Determine the escalation path
- C. Perform vulnerability assessment
- D. Install IPS software
Answer: C
NEW QUESTION # 69
An engineer received an alert of a zero-day vulnerability affecting desktop phones through which an attacker sends a crafted packet to a device, resets the credentials, makes the device unavailable, and allows a default administrator account login. Which step should an engineer take after receiving this alert?
- A. Initiate a triage meeting to acknowledge the vulnerability and its potential impact
- B. Determine company usage of the affected products
- C. Implement restrictions within the VoIP VLANS
- D. Search for a patch to install from the vendor
Answer: A
Explanation:
Upon receiving an alert of a zero-day vulnerability, the first step an engineer should take is to initiate a triage meeting to acknowledge the vulnerability and assess its potential impact2. This step is crucial for understanding the severity of the vulnerability, determining the scope of affected systems, and deciding on the subsequent actions to mitigate the risk. It involves gathering the relevant stakeholders and security experts to evaluate the threat and develop a response plan2.
NEW QUESTION # 70
A company's web server availability was breached by a DDoS attack and was offline for 3 hours because it was not deemed a critical asset in the incident response playbook. Leadership has requested a risk assessment of the asset. An analyst conducted the risk assessment using the threat sources, events, and vulnerabilities. Which additional element is needed to calculate the risk?
- A. event severity and likelihood
- B. assessment scope
- C. risk model framework
- D. incident response playbook
Answer: C
NEW QUESTION # 71
An engineer notices that every Sunday night, there is a two-hour period with a large load of network activity. Upon further investigation, the engineer finds that the activity is from locations around the globe outside the organization's service are a. What are the next steps the engineer must take?
- A. Treat it as a false positive, and accept the SIEM issue as valid to avoid alerts from triggering on weekends.
- B. Review the SIEM and FirePower logs, block all traffic, and document the results of calling the call center.
- C. Define the access points using StealthWatch or SIEM logs, understand services being offered during the hours in Question:, and cross-correlate other source events.
- D. Assign the issue to the incident handling provider because no suspicious activity has been observed during business hours.
Answer: D
NEW QUESTION # 72
......
Truly Beneficial For Your Cisco Exam: https://prepaway.updatedumps.com/Cisco/350-201-updated-exam-dumps.html