350-201 Actual Questions - Instant Download Tests Free Updated Today!
Get instant access of 100% real Cisco 350-201 exam questions with verified answers
NEW QUESTION # 16
A company recently started accepting credit card payments in their local warehouses and is undergoing a PCI audit. Based on business requirements, the company needs to store sensitive authentication data for 45 days. How must data be stored for compliance?
- A. post-authorization by non-issuing entities if there is a documented business justification
- B. post-authorization by non-issuing entities if the data is encrypted and securely stored
- C. by issuers and issuer processors if there is a legitimate reason
- D. by entities that issue the payment cards or that perform support issuing services
Answer: B
NEW QUESTION # 17
An engineer implemented a SOAR workflow to detect and respond to incorrect login attempts and anomalous user behavior. Since the implementation, the security team has received dozens of false positive alerts and negative feedback from system administrators and privileged users. Several legitimate users were tagged as a threat and their accounts blocked, or credentials reset because of unexpected login times and incorrectly typed credentials. How should the workflow be improved to resolve these issues?
- A. Increase incorrect login tries and tune anomalous user behavior not to affect privileged accounts
- B. Add a confirmation step through which SOAR informs the affected user and asks them to confirm whether they made the attempts
- C. Meet with privileged users to increase awareness and modify the rules for threat tags and anomalous behavior alerts
- D. Change the SOAR configuration flow to remove the automatic remediation that is increasing the false positives and triggering threats
Answer: D
NEW QUESTION # 18
Which action should be taken when the HTTP response code 301 is received from a web application?
- A. Increase the allowed user limit.
- B. Confirm the resource's location.
- C. Modify the session timeout setting.
- D. Update the cached header metadata.
Answer: D
NEW QUESTION # 19
The incident response team was notified of detected malware. The team identified the infected hosts, removed the malware, restored the functionality and data of infected systems, and planned a company meeting to improve the incident handling capability. Which step was missed according to the NIST incident handling guide?
- A. Determine the escalation path
- B. Perform vulnerability assessment
- C. Install IPS software
- D. Contain the malware
Answer: B
Explanation:
Explanation/Reference:
NEW QUESTION # 20
Refer to the exhibit.
A threat actor behind a single computer exploited a cloud-based application by sending multiple concurrent API requests. These requests made the application unresponsive. Which solution protects the application from being overloaded and ensures more equitable application access across the end-user community?
- A. Increase the application cache of the total pool of active clients that call the API
- B. Reduce the amount of data that can be fetched from the total pool of active clients that call the API
- C. Limit the number of API calls that a single client is allowed to make
- D. Add restrictions on the edge router on how often a single client can access the API
Answer: C
NEW QUESTION # 21
A new malware variant is discovered hidden in pirated software that is distributed on the Internet. Executives have asked for an organizational risk assessment. The security officer is given a list of all assets. According to NIST, which two elements are missing to calculate the risk assessment? (Choose two.)
- A. incident response playbooks
- B. malware analysis report
- C. key assets and executives
- D. asset vulnerability assessment
- E. report of staff members with asset relations
Answer: B,D
Explanation:
Explanation/Reference: https://cloudogre.com/risk-assessment/
NEW QUESTION # 22
A company launched an e-commerce website with multiple points of sale through internal and external e- stores. Customers access the stores from the public website, and employees access the stores from the intranet with an SSO. Which action is needed to comply with PCI standards for hardening the systems?
- A. Mask PAN numbers
- B. Mask sales details
- C. Encrypt personal data
- D. Encrypt access
Answer: C
NEW QUESTION # 23
Refer to the exhibit.
An engineer must tune the Cisco IOS device to mitigate an attack that is broadcasting a large number of ICMP packets. The attack is sending the victim's spoofed source IP to a network using an IP broadcast address that causes devices in the network to respond back to the source IP address. Which action does the engineer recommend?
- A. Use global configuration command service tcp-keepalives-out
- B. Use subinterface command no ip directed-broadcast
- C. Use command ip verify reverse-path interface
- D. Use logging trap 6
Answer: C
NEW QUESTION # 24
An engineer is moving data from NAS servers in different departments to a combined storage database so that the data can be accessed and analyzed by the organization on-demand. Which data management process is being used?
- A. data regression
- B. data ingestion
- C. data clustering
- D. data obfuscation
Answer: C
NEW QUESTION # 25
Employees receive an email from an executive within the organization that summarizes a recent security breach and requests that employees verify their credentials through a provided link. Several employees report the email as suspicious, and a security analyst is investigating the reports. Which two steps should the analyst take to begin this investigation? (Choose two.)
- A. Communicate with employees to determine who opened the link and isolate the affected assets.
- B. Review the mail server and proxy logs to identify the impact of a potential breach.
- C. Evaluate the intrusion detection system alerts to determine the threat source and attack surface.
- D. Check the email header to identify the sender and analyze the link in an isolated environment.
- E. Examine the firewall and HIPS configuration to identify the exploited vulnerabilities and apply recommended mitigation.
Answer: D,E
Explanation:
Section: (none)
Explanation
NEW QUESTION # 26
The incident response team was notified of detected malware. The team identified the infected hosts, removed the malware, restored the functionality and data of infected systems, and planned a company meeting to improve the incident handling capability. Which step was missed according to the NIST incident handling guide?
- A. Determine the escalation path
- B. Perform vulnerability assessment
- C. Install IPS software
- D. Contain the malware
Answer: B
NEW QUESTION # 27
A SOC analyst is investigating a recent email delivered to a high-value user for a customer whose network their organization monitors. The email includes a suspicious attachment titled "Invoice RE: 0004489". The hash of the file is gathered from the Cisco Email Security Appliance. After searching Open Source Intelligence, no available history of this hash is found anywhere on the web. What is the next step in analyzing this attachment to allow the analyst to gather indicators of compromise?
- A. Run and analyze the DLP Incident Summary Report from the Email Security Appliance
- B. Investigate further in open source repositories using YARA to find matches
- C. Ask the company to execute the payload for real time analysis
- D. Obtain a copy of the file for detonation in a sandbox
Answer: D
NEW QUESTION # 28 
Refer to the exhibit. An engineer is analyzing this Vlan0392-int12-239.pcap file in Wireshark after detecting a suspicious network activity. The origin header for the direct IP connections in the packets was initiated by a google chrome extension on a WebSocket protocol. The engineer checked message payloads to determine what information was being sent off-site but the payloads are obfuscated and unreadable. What does this STIX indicate?
- A. The traffic is legitimate as the google chrome extension is reaching out to check for updates and fetches this information
- B. The extension is not performing as intended because of restrictions since ports 80 and 443 should be accessible
- C. There is a malware that is communicating via encrypted channels to the command and control server
- D. There is a possible data leak because payloads should be encoded as UTF-8 text
Answer: D
NEW QUESTION # 29
Drag and drop the NIST incident response process steps from the left onto the actions that occur in the steps on the right.
Answer:
Explanation:
Reference:
https://www.securitymetrics.com/blog/6-phases-incident-response-plan
NEW QUESTION # 30
Refer to the exhibit.
Where are the browser page rendering permissions displayed?
- A. Cache-Control
- B. X-Frame-Options
- C. Content-Type
- D. X-XSS-Protection
Answer: C
NEW QUESTION # 31
Refer to the exhibit.
An engineer received multiple reports from employees unable to log into systems with the error: The Group Policy Client service failed to logon - Access is denied. Through further analysis, the engineer discovered several unexpected modifications to system settings. Which type of breach is occurring?
- A. denial-of-service
- B. malware break
- C. data theft
- D. elevation of privileges
Answer: D
NEW QUESTION # 32 
Refer to the exhibit. An engineer is investigating a case with suspicious usernames within the active directory.
After the engineer investigates and cross-correlates events from other sources, it appears that the 2 users are privileged, and their creation date matches suspicious network traffic that was initiated from the internal network 2 days prior. Which type of compromise is occurring?
- A. compromised root access
- B. compromised insider
- C. compromised network
- D. compromised database tables
Answer: C
NEW QUESTION # 33
A threat actor used a phishing email to deliver a file with an embedded macro. The file was opened, and a remote code execution attack occurred in a company's infrastructure. Which steps should an engineer take at the recovery stage?
- A. Analyze event logs and restrict network access
- B. Determine the systems involved and deploy available patches
- C. Identify the attack vector and update the IDS signature list
- D. Review access lists and require users to increase password complexity
Answer: A
NEW QUESTION # 34
An organization installed a new application server for IP phones. An automated process fetched user credentials from the Active Directory server, and the application will have access to on-premises and cloud services. Which security threat should be mitigated first?
- A. data exposure from backups
- B. exfiltration during data transfer
- C. attack using default accounts
- D. aligning access control policies
Answer: B
NEW QUESTION # 35
Drag and drop the mitigation steps from the left onto the vulnerabilities they mitigate on the right.
Answer:
Explanation:
NEW QUESTION # 36
What is the HTTP response code when the REST API information requested by the authenticated user cannot be found?
- A. 0
- B. 1
- C. 2
- D. 3
- E. 4
Answer: E
NEW QUESTION # 37
An engineer is analyzing a possible compromise that happened a week ago when the company ? (Choose two.)
- A. Wireshark
- B. SHA512
- C. IPS
- D. firewall
- E. autopsy
Answer: A,D
NEW QUESTION # 38
An engineer is developing an application that requires frequent updates to close feedback loops and enable teams to quickly apply patches. The team wants their code updates to get to market as often as possible. Which software development approach should be used to accomplish these goals?
- A. continuous monitoring
- B. continuous delivery
- C. continuous integration
- D. continuous deployment
Answer: B
NEW QUESTION # 39
Refer to the exhibit.
What is the connection status of the ICMP event?
- A. blocked by an intrusion policy rule
- B. blocked by a configured access policy rule
- C. allowed in the default action
- D. allowed by a configured access policy rule
Answer: D
NEW QUESTION # 40
......
Download Latest & Valid Questions For Cisco 350-201 exam: https://examsboost.pass4training.com/350-201-test-questions.html

