Labour Day Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bigdisc65

CyberOps Associate 200-201 Book

Page: 22 / 23
Question 88

Which two components reduce the attack surface on an endpoint? (Choose two.)

Options:

A.

secure boot

B.

load balancing

C.

increased audit log levels

D.

restricting USB ports

E.

full packet captures at the endpoint

Question 89

What is a difference between tampered and untampered disk images?

Options:

A.

Tampered images have the same stored and computed hash.

B.

Tampered images are used as evidence.

C.

Untampered images are used for forensic investigations.

D.

Untampered images are deliberately altered to preserve as evidence

Question 90

What is the purpose of command and control for network-aware malware?

Options:

A.

It contacts a remote server for commands and updates

B.

It takes over the user account for analysis

C.

It controls and shuts down services on the infected host.

D.

It helps the malware to profile the host

Question 91

Refer to the exhibit.

An analyst was given a PCAP file, which is associated with a recent intrusion event in the company FTP server Which display filters should the analyst use to filter the FTP traffic?

Options:

A.

dstport == FTP

B.

tcp.port==21

C.

tcpport = FTP

D.

dstport = 21

Page: 22 / 23
Exam Code: 200-201
Exam Name: Understanding Cisco Cybersecurity Operations Fundamentals (200-201 CBROPS)
Last Update: Apr 26, 2024
Questions: 311
200-201 pdf

200-201 PDF

$31.5  $90
200-201 Engine

200-201 Testing Engine

$36.75  $105
200-201 PDF + Engine

200-201 PDF + Testing Engine

$49  $140