📘 Free 200-201 Sample Questions
Which event is user interaction?
A
gaining root access
B
executing remote code
C
• reading and writing file permission
D
opening a malicious file
Correct Answer:
D. opening a malicious file
Explanation:
User interaction refers to actions that require the user to actively perform an operation, such as clicking, opening
files, or entering information. Trustworthy site! Pass4surexams helped me get certified on my first attempt. Opening
a malicious file is an example of user interaction because it involves the user manually accessing and executing the
file, which can trigger an attack.
Which security principle requires more than one person is required to perform a critical task?
A
least privilege
B
need to know
C
separation of duties
D
due diligence
Correct Answer:
C. separation of duties
Explanation:
The security principle that requires more than one person is required to perform a critical task is separation of
duties. Separation of duties is a security principle that involves dividing the responsibilities for a critical task among
multiple individuals, so that no single person has complete control over the task. This helps to reduce the risk of
errors, fraud, or abuse, and to ensure that the task is performed accurately and in accordance with established
policies and procedures.
How is attacking a vulnerability categorized?
A
action on objectives
B
. delivery
C
exploitation
D
. installation
Correct Answer:
C. exploitation
Explanation:
Here are the steps of the Kill Chain Model. The example are in the context of the question
1) Reconnaissance - identified vulnerabilities
2) Weaponization - prepare (in lab) the weapon, for example a file with malware code.
3) Delivery - transmit the file (e-mail, website, etc)
4) Exploitation - trigger the weapon (execute the code), exploiting the vulnerability
5) Installation - the weapon installs a backdoor (server)
6) Command and control (C2 or CnC) - connection to the treat actor
7) Actions on objectives - do the job (stealing information, for example)
One of the objectives of information security is to protect the CIA of information and systems.
What does CIA mean in this context?
A
confidentiality, identity, and authorization
B
confidentiality, integrity, and authorization
C
confidentiality, identity, and availability
D
confidentiality, integrity, and availability
Correct Answer:
D. confidentiality, integrity, and availability
Explanation:
Confidentiality refers to the protection of sensitive information from unauthorized access or disclosure. This includes
protecting the privacy of individuals and sensitive business information from unauthorized access or theft. Integrity
refers to the protection of information from unauthorized modification or destruction. This ensures that the
information is accurate and complete, and that it is not tampered with in any way. Availability refers to the ability of
authorized users to access information and systems when they need to. This includes ensuring that systems and
information are always accessible and functioning properly.
Which principle is being followed when an analyst gathers information relevant to a security incident to determine
the appropriate course of action?
A
decision making
B
rapid response
C
data mining
D
. due diligence
Correct Answer:
D. . due diligence
Explanation:
Due diligence is the process of gathering and analyzing all relevant information before making a decision or taking
action. In the context of security incidents, due diligence involves gathering and analyzing all available information
about the incident, such as the nature of the threat, the extent of the damage or potential damage, and the possible
impact on the organization's operations and assets. This information is then used to determine the appropriate
course of action, such as containing and mitigating the threat, restoring systems and data, and identifying and
addressing any underlying vulnerabilities
What is a benefit of agent-based protection when compared to agentless protection?
A
It lowers maintenance costs
B
It provides a centralized platform
C
It collects and detects all traffic locally
D
It manages numerous devices simultaneously
Correct Answer:
C. It collects and detects all traffic locally
Explanation:
Host-based antivirus protection is also known as agent-based. Agent-based antivirus runs on every protected
machine. Agentless antivirus protection performs scans on hosts from a centralized system. Agentless systems have
become popular for virtualized environments in which multiple OS instances are running on a host simultaneously.
Agent-based antivirus running in each virtualized system can be a serious drain on system resources. Agentless
antivirus for virtual hosts involves the use of a special security virtual appliance that performs optimized scanning
tasks on the virtual hosts. An example of this is VMware’s vShield.
What is rule-based detection when compared to statistical detection?
A
proof of a user's identity
B
proof of a user's action
C
likelihood of user's action
D
falsification of a user's identity
Correct Answer:
B. proof of a user's action
Explanation:
Statistical detection uses statistical algorithms and machine learning techniques to analyze patterns of behavior and
determine the likelihood of a particular action being a security threat. But this likelihood can be used to determine
whether an action was performed by a specific user, i.e. to prove the action was performed by the user. On the
other hand, rule-based detection uses predefined rules to determine if a particular action is a security threat
An engineer configured regular expression ".*\.([Dd][Oo][Cc]|[Xx][LI][Ss]|[Pp][Pp][Tt]) HTTP/1.[01]" on Cisco ASA
firewall. What does this regular expression do?
A
. It captures .doc, .xls, and .pdf files in HTTP v1.0 and v1.1.
B
It captures documents in an HTTP network session.
C
It captures Word, Excel, and PowerPoint files in HTTP v1.0 and v1.1.
D
It captures .doc, .xls, and .ppt files extensions in HTTP v1.0.
Correct Answer:
C. It captures Word, Excel, and PowerPoint files in HTTP v1.0 and v1.1.
Explanation:
Pretty self-explanatory, .doc is Word, .xls is Excel, and .ppt is Powerpoint and the two versions of HTTP
Which process is used when IPS events are removed to improve data integrity?
A
data availability
B
data normalization
C
data signature
D
. data protection
Correct Answer:
B. data normalization
Explanation:
Data normalization is the process of capturing, storing, and analyzing data (security-related events, in this case) so
that it exists in only one form. One of the main goals of data normalization is to purge redundant data while
maintaining data integrity. The normalized data is protected by making sure that any manifestation of the same data
elsewhere is only making a reference to the data that is being stored. Intrusion prevention systems (IPSs) focus on
throughput for the most rapid and optimal inline performance. While doing so, in most cases, it is impossible for full
normalization to take place. Traditional IPS devices often rely on shortcuts that only implement partial normalization
and partial inspection. However, this increases the risk of evasions. Fragmentation handling is an example of such an
evasion.
An analyst is investigating an incident in a SOC environment.
Which method is used to identify a session from a group of logs?
A
sequence numbers
B
IP identifier
C
5-tuple
D
timestamps
Correct Answer:
C. 5-tuple
Explanation:
In a security operations center (SOC) environment, one method that could be used to identify a session from a group
of logs is the use of a 5-tuple. A 5-tuple consists of five pieces of information that can be used to identify a specific
network session: the source IP address, source port, destination IP address, destination port, and protocol. By using
this information, an analyst can identify a specific session from a group of logs and track its progress through the
system. Other methods that could be used to identify a session from a group of logs include the use of sequence
numbers, timestamps, or IP identifiers.
Questions: 1-10 out of 462
Continue Full Practice..
GET ALL 462 QUESTIONS