Pass the Cisco CyberOps Associate 200-201 Questions and answers with CertsForce

Viewing page 2 out of 13 pages
Viewing questions 11-20 out of questions
Questions # 11:

Question # 11

Refer to the exhibit. What type of event is occurring?

Options:

A.

Legitimate web browsing activity


B.

Distributed Denial of Service (DDoS) attack


C.

User trying to access a file share


D.

Malware attempting to spread laterally


Expert Solution
Questions # 12:

An offline audit log contains the source IP address of a session suspected to have exploited a vulnerability resulting in system compromise.

Which kind of evidence is this IP address?

Options:

A.

best evidence


B.

corroborative evidence


C.

indirect evidence


D.

forensic evidence


Expert Solution
Questions # 13:

What is a comparison between rule-based and statistical detection?

Options:

A.

Statistical is based on measured data while rule-based uses the evaluated probability approach.


B.

Rule-based Is based on assumptions and statistical uses data Known beforehand.


C.

Rule-based uses data known beforehand and statistical is based on assumptions.


D.

Statistical uses the probability approach while rule-based Is based on measured data.


Expert Solution
Questions # 14:

Which two measures are used by the defense-m-depth strategy? (Choose two)

Options:

A.

Bridge the single connection into multiple.


B.

Divide the network into parts


C.

Split packets into pieces.


D.

Reduce the load on network devices.


E.

Implement the patch management process


Expert Solution
Questions # 15:

Question # 15

Refer to the exhibit. Which alert is identified from this packet?

Options:

A.

SYN flood


B.

SSDP amplification


C.

Fraggle attack


D.

TCP fragmentation attack


Expert Solution
Questions # 16:

What is a difference between tampered and untampered disk images?

Options:

A.

Tampered images have the same stored and computed hash.


B.

Tampered images are used as evidence.


C.

Untampered images are used for forensic investigations.


D.

Untampered images are deliberately altered to preserve as evidence


Expert Solution
Questions # 17:

A security specialist is investigating an incident regarding a recent major breach in the organization. The accounting data from a 24-month period is affected due to a trojan detected in a department's critical server. A security analyst investigates the incident and discovers that an incident response team member who detected a trojan during regular AV scans had made an image of the server for evidence purposes. The security analyst made animage again to compare the hashes of the two images, and they appeared to differ and do not match. Which type of evidence is the security analyst dealing with?

Options:

A.

checksum violated image


B.

integrity violated image


C.

untampered image


D.

tampered image


Expert Solution
Questions # 18:

Refer to the exhibit.

Question # 18

An engineer received an event log file to review. Which technology generated the log?

Options:

A.

NetFlow


B.

proxy


C.

firewall


D.

IDS/IPS


Expert Solution
Questions # 19:

What is the impact of false positive alerts on business compared to true positive?

Options:

A.

True positives affect security as no alarm is raised when an attack has taken place, resulting in a potential breach.


B.

True positive alerts are blocked by mistake as potential attacks affecting application availability.


C.

False positives affect security as no alarm is raised when an attack has taken place, resulting in a potential breach.


D.

False positive alerts are blocked by mistake as potential attacks affecting application availability.


Expert Solution
Questions # 20:

A security expert is working on a copy of the evidence, an ISO file that is saved in CDFS format. Which type of evidence is this file?

Options:

A.

CD data copy prepared in Windows


B.

CD data copy prepared in Mac-based system


C.

CD data copy prepared in Linux system


D.

CD data copy prepared in Android-based system


Expert Solution
Viewing page 2 out of 13 pages
Viewing questions 11-20 out of questions