Get New 2023 Valid Practice CyberOps Professional 350-201 Q&A - Testing Engine [Q36-Q58]

Share

Get New 2023 Valid Practice CyberOps Professional 350-201 Q&A - Testing Engine

350-201 Dumps PDF - 100% Passing Guarantee

NEW QUESTION 36
What is a benefit of key risk indicators?

  • A. improved visibility on quantifiable information
  • B. clear perspective into the risk position of an organization
  • C. clear procedures and processes for organizational risk
  • D. improved mitigation techniques for unknown threats

Answer: D

 

NEW QUESTION 37
Refer to the exhibit.

An engineer must tune the Cisco IOS device to mitigate an attack that is broadcasting a large number of ICMP packets. The attack is sending the victim's spoofed source IP to a network using an IP broadcast address that causes devices in the network to respond back to the source IP address. Which action does the engineer recommend?

  • A. Use subinterface command no ip directed-broadcast
  • B. Use logging trap 6
  • C. Use global configuration command service tcp-keepalives-out
  • D. Use command ip verify reverse-path interface

Answer: D

 

NEW QUESTION 38
How is a SIEM tool used?

  • A. To compare security alerts against configured scenarios and trigger system responses
  • B. To collect and analyze security data from network devices and servers and produce alerts
  • C. To search and compare security data against acceptance standards and generate reports for analysis
  • D. To collect security data from authentication failures and cyber attacks and forward it for analysis

Answer: B

Explanation:
Explanation/Reference: https://www.varonis.com/blog/what-is-siem/

 

NEW QUESTION 39
A company recently completed an internal audit and discovered that there is CSRF vulnerability in 20 of its hosted applications. Based on the audit, which recommendation should an engineer make for patching?

  • A. Update software to patch third-party software
  • B. Fix applications according to the risk scores
  • C. Identify the business applications running on the assets
  • D. Validate CSRF by executing exploits within Metasploit

Answer: B

 

NEW QUESTION 40
An analyst received multiple alerts on the SIEM console of users that are navigating to malicious URLs. The analyst needs to automate the task of receiving alerts and processing the data for further investigations. Three variables are available from the SIEM console to include in an automation script: console_ip, api_token, and reference_set_name. What must be added to this script to receive a successful HTTP response?
#!/usr/bin/python import sys import requests

  • A. console_ip, reference_set_name
  • B. {1}, {3}
  • C. {1}, {2}
  • D. console_ip, api_token

Answer: D

 

NEW QUESTION 41
A SOC analyst is notified by the network monitoring tool that there are unusual types of internal traffic on IP subnet 103.861.2117.0/24. The analyst discovers unexplained encrypted data files on a computer system that belongs on that specific subnet. What is the cause of the issue?

  • A. malware outbreak
  • B. phishing attack
  • C. virus outbreak
  • D. DDoS attack

Answer: A

 

NEW QUESTION 42
An engineer is analyzing a possible compromise that happened a week ago when the company database servers unexpectedly went down. The analysis reveals that attackers tampered with Microsoft SQL Server Resolution Protocol and launched a DDoS attack. The engineer must act quickly to ensure that all systems are protected. Which two tools should be used to detect and mitigate this type of future attack? (Choose two.)

  • A. IPS
  • B. firewall
  • C. autopsy
  • D. Wireshark
  • E. SHA512

Answer: B,D

 

NEW QUESTION 43
How is a SIEM tool used?

  • A. To compare security alerts against configured scenarios and trigger system responses
  • B. To collect and analyze security data from network devices and servers and produce alerts
  • C. To search and compare security data against acceptance standards and generate reports for analysis
  • D. To collect security data from authentication failures and cyber attacks and forward it for analysis

Answer: B

 

NEW QUESTION 44
An engineer wants to review the packet overviews of SNORT alerts. When printing the SNORT alerts, all the packet headers are included, and the file is too large to utilize. Which action is needed to correct this problem?

  • A. Modify the output module rule to "output alert_fast: output filename"
  • B. Modify the output module rule to "output alert_quick: output filename"
  • C. Modify the alert rule to "output alert_syslog: output log"
  • D. Modify the alert rule to "output alert_syslog: output header"

Answer: C

Explanation:
Explanation
Explanation/Reference: https://snort-org-site.s3.amazonaws.com/production/document_files/files/000/000/249/original/ snort_manual.pdf?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAIXACIED2SPMSC7GA%
2F20201231%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20201231T141156Z&X-Amz- Expires=172800&X-Amz-SignedHeaders=host&X-Amz- Signature=e122ab6eb1659e13b3bc6bb2451ce693c0298b76c1962c3743924bc5fd83d382

 

NEW QUESTION 45
Refer to the exhibit.

A security analyst needs to investigate a security incident involving several suspicious connections with a possible attacker. Which tool should the analyst use to identify the source IP of the offender?

  • A. SIEM
  • B. firewall manager
  • C. packet sniffer
  • D. malware analysis

Answer: C

 

NEW QUESTION 46
An organization is using a PKI management server and a SOAR platform to manage the certificate lifecycle. The SOAR platform queries a certificate management tool to check all endpoints for SSL certificates that have either expired or are nearing expiration. Engineers are struggling to manage problematic certificates outside of PKI management since deploying certificates and tracking them requires searching server owners manually. Which action will improve workflow automation?

  • A. Integrate a PKI solution within SOAR to create certificates within the SOAR engines to track, update, and monitor problematic certificates.
  • B. Implement a new workflow for SOAR to fetch a report of assets that are outside of the PKI zone, sort assets by certification management leads and automate alerts that updates are needed.
  • C. Implement a new workflow within SOAR to create tickets in the incident response system, assign problematic certificate update requests to server owners, and register change requests.
  • D. Integrate a SOAR solution with Active Directory to pull server owner details from the AD and send an automated email for problematic certificates requesting updates.

Answer: B

 

NEW QUESTION 47
Refer to the exhibit.

What is occurring in this packet capture?

  • A. DNS tunneling
  • B. TCP flood
  • C. DNS flood
  • D. TCP port scan

Answer: B

 

NEW QUESTION 48
A security architect in an automotive factory is working on the Cyber Security Management System and is implementing procedures and creating policies to prevent attacks. Which standard must the architect apply?

  • A. IEC62443
  • B. IEC62439-3
  • C. IEC62439-2
  • D. IEC62446

Answer: A

 

NEW QUESTION 49
Refer to the exhibit.

Which asset has the highest risk value?

  • A. payment process
  • B. website
  • C. secretary workstation
  • D. servers

Answer: A

 

NEW QUESTION 50
A SOC team receives multiple alerts by a rule that detects requests to malicious URLs and informs the incident response team to block the malicious URLs requested on the firewall. Which action will improve the effectiveness of the process?

  • A. Inform the incident response team by enabling an automated email response when the rule is triggered.
  • B. Block local to remote HTTP/HTTPS requests on the firewall for users who triggered the rule.
  • C. Inform the user by enabling an automated email response when the rule is triggered.
  • D. Create an automation script for blocking URLs on the firewall when the rule is triggered.

Answer: B

 

NEW QUESTION 51
Refer to the exhibit.

The Cisco Secure Network Analytics (Stealthwatch) console alerted with "New Malware Server Discovered" and the IOC indicates communication from an end-user desktop to a Zeus C&C Server. Drag and drop the actions that the analyst should take from the left into the order on the right to investigate and remediate this IOC.

Answer:

Explanation:

 

NEW QUESTION 52
A malware outbreak is detected by the SIEM and is confirmed as a true positive. The incident response team follows the playbook to mitigate the threat. What is the first action for the incident response team?

  • A. Assess the network for unexpected behavior
  • B. Patch detected vulnerabilities from critical hosts
  • C. Isolate critical hosts from the network
  • D. Perform analysis based on the established risk factors

Answer: C

 

NEW QUESTION 53

Refer to the exhibit. An engineer is reverse engineering a suspicious file by examining its resources. What does this file indicate?

  • A. an archived malware
  • B. a DOS MZ executable format
  • C. a Windows executable file
  • D. a MS-DOS executable archive

Answer: C

Explanation:
Explanation/Reference: https://stackoverflow.com/questions/2577545/why-is-this-program-cannot-be-run-in-dos-mode-text- present-in-dll-files#:~:text=The%20linker%20places%20a%20default,using%20the%20%2FSTUB%20linker%
20option.&text=This%20information%20enables%20Windows%20to,has%20an%20MS-DOS%20stub.

 

NEW QUESTION 54
An engineer is utilizing interactive behavior analysis to test malware in a sandbox environment to see how the malware performs when it is successfully executed. A location is secured to perform reverse engineering on a piece of malware. What is the next step the engineer should take to analyze this malware?

  • A. Unpack the file in a sandbox to see how it reacts
  • B. Run the program through a debugger to see the sequential actions
  • C. Disassemble the malware to understand how it was constructed
  • D. Research the malware online to see if there are noted findings

Answer: D

 

NEW QUESTION 55
According to GDPR, what should be done with data to ensure its confidentiality, integrity, and availability?

  • A. Perform awareness testing
  • B. Conduct a data protection impact assessment
  • C. Perform a vulnerability assessment
  • D. Conduct penetration testing

Answer: B

Explanation:
Explanation/Reference: https://apdcat.gencat.cat/web/.content/03-documentacio/ Reglament_general_de_proteccio_de_dades/documents/DPIA-Guide.pdf

 

NEW QUESTION 56

Refer to the exhibit. IDS is producing an increased amount of false positive events about brute force attempts on the organization's mail server. How should the Snort rule be modified to improve performance?

  • A. Set the rule to track the source IP
  • B. Tune the count and seconds threshold of the rule
  • C. Change the rule content match to case sensitive
  • D. Block list of internal IPs from the rule

Answer: C

 

NEW QUESTION 57
Refer to the exhibit.

Where are the browser page rendering permissions displayed?

  • A. x-frame-options
  • B. x-content-type-options
  • C. x-test-debug
  • D. x-xss-protection

Answer: B

 

NEW QUESTION 58
......

350-201 Braindumps Real Exam Updated on Mar 15, 2023 with 141 Questions: https://pass4sure.validdumps.top/350-201-exam-torrent.html