Get Latest Oct-2021 Conduct effective penetration tests using TestValid 200-201 exam [Q49-Q68]

Share

Get Latest [Oct-2021] Conduct effective penetration tests using  TestValid 200-201

Penetration testers simulate 200-201 exam PDF

NEW QUESTION 49
What is the difference between an attack vector and attack surface?

  • A. An attack vector identifies components that can be exploited; and an attack surface identifies the potential path an attack can take to penetrate the network.
  • B. An attack surface recognizes which network parts are vulnerable to an attack; and an attack vector identifies which attacks are possible with these vulnerabilities.
  • C. An attack vector identifies the potential outcomes of an attack; and an attack surface launches an attack using several methods against the identified vulnerabilities.
  • D. An attack surface identifies vulnerabilities that require user input or validation; and an attack vector identifies vulnerabilities that are independent of user actions.

Answer: B

Explanation:
Section: Security Concepts

 

NEW QUESTION 50
Which NIST IR category stakeholder is responsible for coordinating incident response among various business units, minimizing damage, and reporting to regulatory agencies?

  • A. CSIRT
  • B. PSIRT
  • C. public affairs
  • D. management

Answer: D

Explanation:
Section: Security Policies and Procedures

 

NEW QUESTION 51
Refer to the exhibit.

What is the potential threat identified in this Stealthwatch dashboard?

  • A. A policy violation is active for host 10.201.3.149.
  • B. A host on the network is sending a DDoS attack to another inside host.
  • C. There are three active data exfiltration alerts.
  • D. A policy violation is active for host 10.10.101.24.

Answer: C

 

NEW QUESTION 52
An offline audit log contains the source IP address of a session suspected to have exploited a vulnerability resulting in system compromise.
Which kind of evidence is this IP address?

  • A. forensic evidence
  • B. indirect evidence
  • C. best evidence
  • D. corroborative evidence

Answer: D

 

NEW QUESTION 53
Which principle is being followed when an analyst gathers information relevant to a security incident to determine the appropriate course of action?

  • A. rapid response
  • B. decision making
  • C. due diligence
  • D. data mining

Answer: B

 

NEW QUESTION 54
What are two differences in how tampered and untampered disk images affect a security incident? (Choose two.)

  • A. Tampered images are used in the incident recovery process
  • B. Untampered images are used in the security investigation process
  • C. The image is tampered if the stored hash and the computed hash match
  • D. The image is untampered if the stored hash and the computed hash match
  • E. Tampered images are used in the security investigation process

Answer: D,E

 

NEW QUESTION 55
Refer to the exhibit.

What is depicted in the exhibit?

  • A. Apache logs
  • B. IIS logs
  • C. Windows Event logs
  • D. UNIX-based syslog

Answer: D

 

NEW QUESTION 56
Refer to the exhibit.

Which event is occurring?

  • A. A URL is being evaluated to see if it has a malicious binary
  • B. A binary on VM cuckoo1 is being submitted for evaluation
  • C. A binary is being submitted to run on VM cuckoo1
  • D. A binary named "submit" is running on VM cuckoo1.

Answer: B

 

NEW QUESTION 57
Which action prevents buffer overflow attacks?

  • A. variable randomization
  • B. using web based applications
  • C. using a Linux operating system
  • D. input sanitization

Answer: D

 

NEW QUESTION 58

Refer to the exhibit. Which application protocol is in this PCAP file?

  • A. TCP
  • B. SSH
  • C. TLS
  • D. HTTP

Answer: A

Explanation:
Section: Network Intrusion Analysis

 

NEW QUESTION 59
A company receptionist received a threatening call referencing stealing assets and did not take any action assuming it was a social engineering attempt. Within 48 hours, multiple assets were breached, affecting the confidentiality of sensitive information. What is the threat actor in this incident?

  • A. company assets that are threatened
  • B. victims of the attack
  • C. customer assets that are threatened
  • D. perpetrators of the attack

Answer: C

 

NEW QUESTION 60
Refer to the exhibit.

What is occurring in this network traffic?

  • A. Flood of ACK packets coming from a single source IP to multiple destination IPs.
  • B. High rate of ACK packets being sent from a single source IP towards multiple destination IPs.
  • C. High rate of SYN packets being sent from a multiple source towards a single destination IP.
  • D. Flood of SYN packets coming from a single source IP to a single destination IP.

Answer: D

 

NEW QUESTION 61

Refer to the exhibit. What information is depicted?

  • A. IIS data
  • B. IPS event data
  • C. NetFlow data
  • D. network discovery event

Answer: C

 

NEW QUESTION 62
Which data format is the most efficient to build a baseline of traffic seen over an extended period of time?

  • A. NetFlow
  • B. syslog messages
  • C. full packet capture
  • D. firewall event logs

Answer: A

 

NEW QUESTION 63
Refer to the exhibit.

What information is depicted?

  • A. IIS data
  • B. IPS event data
  • C. NetFlow data
  • D. network discovery event

Answer: C

 

NEW QUESTION 64
Drag and drop the technology on the left onto the data type the technology provides on the right.

Answer:

Explanation:

 

NEW QUESTION 65
Which metric in CVSS indicates an attack that takes a destination bank account number and replaces it with a different bank account number?

  • A. scope
  • B. confidentiality
  • C. integrity
  • D. availability

Answer: C

 

NEW QUESTION 66
Drag and drop the security concept on the left onto the example of that concept on the right.

Answer:

Explanation:

 

NEW QUESTION 67
An analyst received a ticket regarding a degraded processing capability for one of the HR department's servers. On the same day, an engineer noticed a disabled antivirus software and was not able to determine when or why it occurred. According to the NIST Incident Handling Guide, what is the next phase of this investigation?

  • A. Detection
  • B. Analysis
  • C. Eradication
  • D. Recovery

Answer: A

 

NEW QUESTION 68
......

Tested Material Used To 200-201 Test Engine: https://www.testvalid.com/200-201-exam-collection.html

Steps Necessary To Pass The 200-201 Exam: https://drive.google.com/open?id=1jZEucwwrpMq8fDO_jc_vwUkYfELrUtem