Get Latest [Oct-2021] Conduct effective penetration tests using TestValid 200-201
Penetration testers simulate 200-201 exam PDF
NEW QUESTION 49
What is the difference between an attack vector and attack surface?
- A. An attack vector identifies components that can be exploited; and an attack surface identifies the potential path an attack can take to penetrate the network.
- B. An attack surface recognizes which network parts are vulnerable to an attack; and an attack vector identifies which attacks are possible with these vulnerabilities.
- C. An attack vector identifies the potential outcomes of an attack; and an attack surface launches an attack using several methods against the identified vulnerabilities.
- D. An attack surface identifies vulnerabilities that require user input or validation; and an attack vector identifies vulnerabilities that are independent of user actions.
Answer: B
Explanation:
Section: Security Concepts
NEW QUESTION 50
Which NIST IR category stakeholder is responsible for coordinating incident response among various business units, minimizing damage, and reporting to regulatory agencies?
- A. CSIRT
- B. PSIRT
- C. public affairs
- D. management
Answer: D
Explanation:
Section: Security Policies and Procedures
NEW QUESTION 51
Refer to the exhibit.
What is the potential threat identified in this Stealthwatch dashboard?
- A. A policy violation is active for host 10.201.3.149.
- B. A host on the network is sending a DDoS attack to another inside host.
- C. There are three active data exfiltration alerts.
- D. A policy violation is active for host 10.10.101.24.
Answer: C
NEW QUESTION 52
An offline audit log contains the source IP address of a session suspected to have exploited a vulnerability resulting in system compromise.
Which kind of evidence is this IP address?
- A. forensic evidence
- B. indirect evidence
- C. best evidence
- D. corroborative evidence
Answer: D
NEW QUESTION 53
Which principle is being followed when an analyst gathers information relevant to a security incident to determine the appropriate course of action?
- A. rapid response
- B. decision making
- C. due diligence
- D. data mining
Answer: B
NEW QUESTION 54
What are two differences in how tampered and untampered disk images affect a security incident? (Choose two.)
- A. Tampered images are used in the incident recovery process
- B. Untampered images are used in the security investigation process
- C. The image is tampered if the stored hash and the computed hash match
- D. The image is untampered if the stored hash and the computed hash match
- E. Tampered images are used in the security investigation process
Answer: D,E
NEW QUESTION 55
Refer to the exhibit.
What is depicted in the exhibit?
- A. Apache logs
- B. IIS logs
- C. Windows Event logs
- D. UNIX-based syslog
Answer: D
NEW QUESTION 56
Refer to the exhibit.
Which event is occurring?
- A. A URL is being evaluated to see if it has a malicious binary
- B. A binary on VM cuckoo1 is being submitted for evaluation
- C. A binary is being submitted to run on VM cuckoo1
- D. A binary named "submit" is running on VM cuckoo1.
Answer: B
NEW QUESTION 57
Which action prevents buffer overflow attacks?
- A. variable randomization
- B. using web based applications
- C. using a Linux operating system
- D. input sanitization
Answer: D
NEW QUESTION 58 
Refer to the exhibit. Which application protocol is in this PCAP file?
- A. TCP
- B. SSH
- C. TLS
- D. HTTP
Answer: A
Explanation:
Section: Network Intrusion Analysis
NEW QUESTION 59
A company receptionist received a threatening call referencing stealing assets and did not take any action assuming it was a social engineering attempt. Within 48 hours, multiple assets were breached, affecting the confidentiality of sensitive information. What is the threat actor in this incident?
- A. company assets that are threatened
- B. victims of the attack
- C. customer assets that are threatened
- D. perpetrators of the attack
Answer: C
NEW QUESTION 60
Refer to the exhibit.
What is occurring in this network traffic?
- A. Flood of ACK packets coming from a single source IP to multiple destination IPs.
- B. High rate of ACK packets being sent from a single source IP towards multiple destination IPs.
- C. High rate of SYN packets being sent from a multiple source towards a single destination IP.
- D. Flood of SYN packets coming from a single source IP to a single destination IP.
Answer: D
NEW QUESTION 61 
Refer to the exhibit. What information is depicted?
- A. IIS data
- B. IPS event data
- C. NetFlow data
- D. network discovery event
Answer: C
NEW QUESTION 62
Which data format is the most efficient to build a baseline of traffic seen over an extended period of time?
- A. NetFlow
- B. syslog messages
- C. full packet capture
- D. firewall event logs
Answer: A
NEW QUESTION 63
Refer to the exhibit.
What information is depicted?
- A. IIS data
- B. IPS event data
- C. NetFlow data
- D. network discovery event
Answer: C
NEW QUESTION 64
Drag and drop the technology on the left onto the data type the technology provides on the right.
Answer:
Explanation:

NEW QUESTION 65
Which metric in CVSS indicates an attack that takes a destination bank account number and replaces it with a different bank account number?
- A. scope
- B. confidentiality
- C. integrity
- D. availability
Answer: C
NEW QUESTION 66
Drag and drop the security concept on the left onto the example of that concept on the right.
Answer:
Explanation:

NEW QUESTION 67
An analyst received a ticket regarding a degraded processing capability for one of the HR department's servers. On the same day, an engineer noticed a disabled antivirus software and was not able to determine when or why it occurred. According to the NIST Incident Handling Guide, what is the next phase of this investigation?
- A. Detection
- B. Analysis
- C. Eradication
- D. Recovery
Answer: A
NEW QUESTION 68
......
Tested Material Used To 200-201 Test Engine: https://www.testvalid.com/200-201-exam-collection.html
Steps Necessary To Pass The 200-201 Exam: https://drive.google.com/open?id=1jZEucwwrpMq8fDO_jc_vwUkYfELrUtem