Free 350-201 Exam Braindumps (page: 11)

Page 10 of 35

An engineer received an alert of a zero-day vulnerability affecting desktop phones through which an attacker sends a crafted packet to a device, resets the credentials, makes the device unavailable, and allows a default administrator account login. Which step should an engineer take after receiving this alert?

  1. Initiate a triage meeting to acknowledge the vulnerability and its potential impact
  2. Determine company usage of the affected products
  3. Search for a patch to install from the vendor
  4. Implement restrictions within the VoIP VLANS

Answer(s): C



Refer to the exhibit. Which code snippet will parse the response to identify the status of the domain as malicious, clean or undefined?





Answer(s): C



An engineer receives an incident ticket with hundreds of intrusion alerts that require investigation. An analysis of the incident log shows that the alerts are from trusted IP addresses and internal devices. The final incident report stated that these alerts were false positives and that no intrusions were detected. What action should be taken to harden the network?

  1. Move the IPS to after the firewall facing the internal network
  2. Move the IPS to before the firewall facing the outside network
  3. Configure the proxy service on the IPS
  4. Configure reverse port forwarding on the IPS

Answer(s): C



A SOC team is informed that a UK-based user will be traveling between three countries over the next 60 days. Having the names of the 3 destination countries and the user's working hours, what must the analyst do next to detect an abnormal behavior?

  1. Create a rule triggered by 3 failed VPN connection attempts in an 8-hour period
  2. Create a rule triggered by 1 successful VPN connection from any nondestination country
  3. Create a rule triggered by multiple successful VPN connections from the destination countries
  4. Analyze the logs from all countries related to this user during the traveling period

Answer(s): D






Post your Comments and Discuss Cisco® 350-201 exam with other Community members:

350-201 Discussions & Posts