Spring Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Free 200-201 Questions Attempt

Page: 32 / 36
Total 476 questions

Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS) Questions and Answers

Question 125

Which piece of information is needed for attribution in an investigation?

Options:

A.

proxy logs showing the source RFC 1918 IP addresses

B.

RDP allowed from the Internet

C.

known threat actor behavior

D.

802.1x RADIUS authentication pass arid fail logs

Question 126

Refer to the exhibit.

Which type of log is displayed?

Options:

A.

proxy

B.

NetFlow

C.

IDS

D.

sys

Question 127

What is a difference between SI EM and SOAR security systems?

Options:

A.

SOAR ingests numerous types of logs and event data infrastructure components and SIEM can fetch data from endpoint security software and external threat intelligence feeds

B.

SOAR collects and stores security data at a central point and then converts it into actionable intelligence, and SIEM enables SOC teams to automate and orchestrate manual tasks

C.

SIEM raises alerts in the event of detecting any suspicious activity, and SOAR automates investigation path workflows and reduces time spent on alerts

D.

SIEM combines data collecting, standardization, case management, and analytics for a defense-in-depth concept, and SOAR collects security data antivirus logs, firewall logs, and hashes of downloaded files

Question 128

Refer to the exhibit. A security engineer receives several alerts from the SNORT IPS/IDS reporting malicious traffic. What should the engineer understand by examining the SNORT logs?

Options:

A.

A remote threat performs an EternalBlue attack on a Windows system on several ports.

B.

An inside threat performs an EternalBlue attack on hosts 192.168.2.101 and 192.168.200.10 on port 445.

C.

A remote threat performs an EternalBlue attack on several hosts and different ports.

D.

An inside threat performs an EternalBlue attack on a Windows system on port 445.

Page: 32 / 36
Total 476 questions