Spring Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS)

Last Update 7 hours ago Total Questions : 476

The Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS) content is now fully updated, with all current exam questions added 7 hours ago. Deciding to include 200-201 practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our 200-201 exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these 200-201 sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS) practice test comfortably within the allotted time.

Question # 131

Which access control should a chief information security officer select to protect extremely sensitive data categorized at various levels of confidentiality?

A.

MAC; each object owner is responsible to provide access only to authorized users.

B.

MAC; access control decisions are centrally managed and minimize the human error probability.

C.

DAC; access control decisions are centrally managed and minimize the human error probability.

D.

DAC; each object owner is responsible to provide access only to authorized users.

Question # 132

An engineer received an alert affecting the degraded performance of a critical server Analysis showed a heavy CPU and memory load What is the next step the engineer should take to investigate this resource usage7

A.

Run " ps -ef to understand which processes are taking a high amount of resources

B.

Run " ps -u " to find out who executed additional processes that caused a high load on a server

C.

Run " ps -m " to capture the existing state of daemons and map the required processes to find the gap

D.

Run " ps -d " to decrease the priority state of high-load processes to avoid resource exhaustion

Question # 133

Refer to the exhibit.

What is occurring?

A.

Identifying possible malware communications and botnet activity

B.

Monitoring of encrypted and unencrypted web sessions for diagnostics.

C.

Analysis of traffic flows during network capacity testing

D.

Review of session logs for performance optimization in a distributed application environment

Question # 134

A company encountered a breach on its web servers using IIS 7 5 Dunng the investigation, an engineer discovered that an attacker read and altered the data on a secure communication using TLS 1 2 and intercepted sensitive information by downgrading a connection to export-grade cryptography. The engineer must mitigate similar incidents in the future and ensure that clients and servers always negotiate with the most secure protocol versions and cryptographic parameters. Which action does the engineer recommend?

A.

Upgrade to TLS v1 3.

B.

Install the latest IIS version.

C.

Downgrade to TLS 1.1.

D.

Deploy an intrusion detection system

Question # 135

What is the difference between inline traffic interrogation and traffic mirroring?

A.

Inline interrogation is less complex as traffic mirroring applies additional tags to data.

B.

Traffic mirroring copies the traffic rather than forwarding it directly to the analysis tools

C.

Inline replicates the traffic to preserve integrity rather than modifying packets before sending them to other analysis tools.

D.

Traffic mirroring results in faster traffic analysis and inline is considerably slower due to latency.

Question # 136

An organization is cooperating with several third-party companies. Data exchange is on an unsecured channel using port 80 Internal employees use the FTP service to upload and download sensitive data An engineer must ensure confidentiality while preserving the integrity of the communication. Which technology must the engineer implement in this scenario ' ?

A.

X.509 certificates

B.

RADIUS server

C.

CA server

D.

web application firewall

Question # 137

Refer to the exhibit. A network engineer received a report that a host is communicating with unknown domains on the internet. The network engineer collected packet capture but could not determine the technique or the payload used. What technique is the attacker using?

A.

amplification

B.

teardrop

C.

session hijacking

D.

tunneling

Question # 138

Why is HTTPS traffic difficult to screen?

A.

HTTPS is used internally and screening traffic (or external parties is hard due to isolation.

B.

The communication is encrypted and the data in transit is secured.

C.

Digital certificates secure the session, and the data is sent at random intervals.

D.

Traffic is tunneled to a specific destination and is inaccessible to others except for the receiver.

Question # 139

Which SOC metric represents the time to stop the incident from causing further damage to systems or data?

A.

Mean Time to Acknowledge (MTTA)

B.

Mean Time to Detect (MTTR)

C.

Mean Time to Respond (MTTR)

D.

Mean Time to Contain (MTTC)

Question # 140

Which step in the incident response process researches an attacking host through logs in a SIEM?

A.

detection and analysis

B.

preparation

C.

eradication

D.

containment

Go to page: