Clear your concepts with 350-201 Questions Before Attempting Real exam [Q45-Q64]

Rate this post

Clear your concepts with 350-201 Questions Before Attempting Real exam

Get professional help from our 350-201 Dumps PDF

NO.45

Refer to the exhibit. At which stage of the threat kill chain is an attacker, based on these URIs of inbound web requests from known malicious Internet scanners?

 
 
 
 

NO.46 A SOC team is investigating a recent, targeted social engineering attack on multiple employees. Cross- correlated log analysis revealed that two hours before the attack, multiple assets received requests on TCP port 79. Which action should be taken by the SOC team to mitigate this attack?

 
 
 
 

NO.47 Refer to the exhibit.

The Cisco Secure Network Analytics (Stealthwatch) console alerted with “New Malware Server Discovered” and the IOC indicates communication from an end-user desktop to a Zeus C&C Server. Drag and drop the actions that the analyst should take from the left into the order on the right to investigate and remediate this IOC.

NO.48 Refer to the exhibit.

Based on the detected vulnerabilities, what is the next recommended mitigation step?

 
 
 
 

NO.49 Refer to the exhibit.

Where is the MIME type that should be followed indicated?

 
 
 
 

NO.50 A security architect is working in a processing center and must implement a DLP solution to detect and prevent any type of copy and paste attempts of sensitive data within unapproved applications and removable devices. Which technical architecture must be used?

 
 
 
 

NO.51 An organization lost connectivity to critical servers, and users cannot access business applications and internal websites. An engineer checks the network devices to investigate the outage and determines that all devices are functioning. Drag and drop the steps from the left into the sequence on the right to continue investigating this issue. Not all options are used.

NO.52 An organization had an incident with the network availability during which devices unexpectedly malfunctioned. An engineer is investigating the incident and found that the memory pool buffer usage reached a peak before the malfunction. Which action should the engineer take to prevent this issue from reoccurring?

 
 
 
 

NO.53 Refer to the exhibit.

An organization is using an internal application for printing documents that requires a separate registration on the website. The application allows format-free user creation, and users must match these required conditions to comply with the company’s user creation policy:
minimum length: 3
usernames can only use letters, numbers, dots, and underscores
usernames cannot begin with a number
The application administrator has to manually change and track these daily to ensure compliance. An engineer is tasked to implement a script to automate the process according to the company user creation policy. The engineer implemented this piece of code within the application, but users are still able to create format-free usernames. Which change is needed to apply the restrictions?

 
 
 
 

NO.54 Which action should be taken when the HTTP response code 301 is received from a web application?

 
 
 
 

NO.55 Refer to the exhibit.

IDS is producing an increased amount of false positive events about brute force attempts on the organization’s mail server. How should the Snort rule be modified to improve performance?

 
 
 
 

NO.56 An engineer is analyzing a possible compromise that happened a week ago when the company ? (Choose two.)

 
 
 
 
 

NO.57 A SIEM tool fires an alert about a VPN connection attempt from an unusual location. The incident response team validates that an attacker has installed a remote access tool on a user’s laptop while traveling. The attacker has the user’s credentials and is attempting to connect to the network.
What is the next step in handling the incident?

 
 
 
 

NO.58 An analyst is alerted for a malicious file hash. After analysis, the analyst determined that an internal workstation is communicating over port 80 with an external server and that the file hash is associated with Duqu malware. Which tactics, techniques, and procedures align with this analysis?

 
 
 
 

NO.59 Drag and drop the components from the left onto the phases of the CI/CD pipeline on the right.

NO.60 Refer to the exhibit.

An engineer is performing static analysis of a file received and reported by a user. Which risk is indicated in this STIX?

 
 
 
 

NO.61 Drag and drop the function on the left onto the mechanism on the right.

NO.62 An organization is using a PKI management server and a SOAR platform to manage the certificate lifecycle. The SOAR platform queries a certificate management tool to check all endpoints for SSL certificates that have either expired or are nearing expiration. Engineers are struggling to manage problematic certificates outside of PKI management since deploying certificates and tracking them requires searching server owners manually. Which action will improve workflow automation?

 
 
 
 

NO.63 A security expert is investigating a breach that resulted in a $32 million loss from customer accounts. Hackers were able to steal API keys and two-factor codes due to a vulnerability that was introduced in a new code a few weeks before the attack. Which step was missed that would have prevented this breach?

 
 
 
 

NO.64 Refer to the exhibit.

Cisco Rapid Threat Containment using Cisco Secure Network Analytics (Stealthwatch) and ISE detects the threat of malware-infected 802.1x authenticated endpoints and places that endpoint into a Quarantine VLAN using Adaptive Network Control policy. Which telemetry feeds were correlated with SMC to identify the malware?

 
 
 
 

Achieve the 350-201 Exam Best Results with Help from Cisco Certified Experts: https://www.it-tests.com/350-201.html

         

Related Links: myportal.utt.edu.tt www.stes.tyc.edu.tw jacobscott67888.blogspot.com www.stes.tyc.edu.tw www.stes.tyc.edu.tw myportal.utt.edu.tt