Ultimate Guide to the 350-201 - Latest Feb 21, 2022 Edition Available Now
2022 Updated Verified Pass 350-201 Exam - Real Questions and Answers
NEW QUESTION 22
A security architect is working in a processing center and must implement a DLP solution to detect and prevent any type of copy and paste attempts of sensitive data within unapproved applications and removable devices.
Which technical architecture must be used?
- A. DLP for removable data
- B. DLP for data in motion
- C. DLP for data in use
- D. DLP for data at rest
Answer: C
Explanation:
Explanation/Reference: https://www.endpointprotector.com/blog/what-is-data-loss-prevention-dlp/
NEW QUESTION 23
Refer to the exhibit. Which asset has the highest risk value?
- A. secretary workstation
- B. servers
- C. payment process
- D. website
Answer: C
NEW QUESTION 24
A threat actor has crafted and sent a spear-phishing email with what appears to be a trustworthy link to the site of a conference that an employee recently attended. The employee clicked the link and was redirected to a malicious site through which the employee downloaded a PDF attachment infected with ransomware. The employee opened the attachment, which exploited vulnerabilities on the desktop. The ransomware is now installed and is calling back to its command and control server. Which security solution is needed at this stage to mitigate the attack?
- A. endpoint security solution
- B. web security solution
- C. network security solution
- D. email security solution
Answer: C
NEW QUESTION 25
Refer to the exhibit.
Which command was executed in PowerShell to generate this log?
- A. Get-WinEvent -ListLog*
- B. Get-EventLog -LogName*
- C. Get-WinEvent -ListLog* -ComputerName localhost
- D. Get-EventLog -List
Answer: B
NEW QUESTION 26
According to GDPR, what should be done with data to ensure its confidentiality, integrity, and availability?
- A. Conduct penetration testing
- B. Perform awareness testing
- C. Perform a vulnerability assessment
- D. Conduct a data protection impact assessment
Answer: D
NEW QUESTION 27
An organization installed a new application server for IP phones. An automated process fetched user credentials from the Active Directory server, and the application will have access to on-premises and cloud services. Which security threat should be mitigated first?
- A. data exposure from backups
- B. aligning access control policies
- C. attack using default accounts
- D. exfiltration during data transfer
Answer: D
NEW QUESTION 28
An engineer received an alert of a zero-day vulnerability affecting desktop phones through which an attacker sends a crafted packet to a device, resets the credentials, makes the device unavailable, and allows a default administrator account login. Which step should an engineer take after receiving this alert?
- A. Determine company usage of the affected products
- B. Implement restrictions within the VoIP VLANS
- C. Initiate a triage meeting to acknowledge the vulnerability and its potential impact
- D. Search for a patch to install from the vendor
Answer: D
NEW QUESTION 29
A security incident affected an organization's critical business services, and the customer-side web API became unresponsive and crashed. An investigation revealed a spike of API call requests and a high number of inactive sessions during the incident. Which two recommendations should the engineers make to prevent similar incidents in the future? (Choose two.)
- A. Decrease simultaneous API responses.
- B. Automate server-side error reporting for customers.
- C. Determine API rate-limiting requirements.
- D. Implement API key maintenance.
- E. Configure shorter timeout periods.
Answer: B,C
NEW QUESTION 30
An organization had an incident with the network availability during which devices unexpectedly malfunctioned. An engineer is investigating the incident and found that the memory pool buffer usage reached a peak before the malfunction. Which action should the engineer take to prevent this issue from reoccurring?
- A. Enable memory tracing notifications.
- B. Disable CPU threshold trap toward the SNMP server.
- C. Disable memory limit.
- D. Enable memory threshold notifications.
Answer: D
NEW QUESTION 31
How is a SIEM tool used?
- A. To collect security data from authentication failures and cyber attacks and forward it for analysis
- B. To search and compare security data against acceptance standards and generate reports for analysis
- C. To compare security alerts against configured scenarios and trigger system responses
- D. To collect and analyze security data from network devices and servers and produce alerts
Answer: D
Explanation:
Explanation/Reference: https://www.varonis.com/blog/what-is-siem/
NEW QUESTION 32
Which bash command will print all lines from the "colors.txt" file containing the non case-sensitive pattern "Yellow"?
- A. grep -i "yellow" colors.txt
- B. locate "yellow" colors.txt
- C. grep "Yellow" colors.txt
- D. locate -i "Yellow" colors.txt
Answer: A
NEW QUESTION 33
Refer to the exhibit.
A threat actor behind a single computer exploited a cloud-based application by sending multiple concurrent API requests. These requests made the application unresponsive. Which solution protects the application from being overloaded and ensures more equitable application access across the end-user community?
- A. Add restrictions on the edge router on how often a single client can access the API
- B. Increase the application cache of the total pool of active clients that call the API
- C. Limit the number of API calls that a single client is allowed to make
- D. Reduce the amount of data that can be fetched from the total pool of active clients that call the API
Answer: C
NEW QUESTION 34
An analyst received multiple alerts on the SIEM console of users that are navigating to malicious URLs. The analyst needs to automate the task of receiving alerts and processing the data for further investigations. Three variables are available from the SIEM console to include in an automation script: console_ip, api_token, and reference_set_name. What must be added to this script to receive a successful HTTP response?
#!/usr/bin/python import sys import requests
- A. console_ip, api_token
- B. {1}, {2}
- C. {1}, {3}
- D. console_ip, reference_set_name
Answer: A
NEW QUESTION 35
A SOC analyst is investigating a recent email delivered to a high-value user for a customer whose network their organization monitors. The email includes a suspicious attachment titled "Invoice RE: 0004489". The hash of the file is gathered from the Cisco Email Security Appliance. After searching Open Source Intelligence, no available history of this hash is found anywhere on the web. What is the next step in analyzing this attachment to allow the analyst to gather indicators of compromise?
- A. Obtain a copy of the file for detonation in a sandbox
- B. Ask the company to execute the payload for real time analysis
- C. Run and analyze the DLP Incident Summary Report from the Email Security Appliance
- D. Investigate further in open source repositories using YARA to find matches
Answer: A
NEW QUESTION 36
A malware outbreak is detected by the SIEM and is confirmed as a true positive. The incident response team follows the playbook to mitigate the threat. What is the first action for the incident response team?
- A. Isolate critical hosts from the network
- B. Perform analysis based on the established risk factors
- C. Assess the network for unexpected behavior
- D. Patch detected vulnerabilities from critical hosts
Answer: A
NEW QUESTION 37
Refer to the exhibit.
An engineer received a report that an attacker has compromised a workstation and gained access to sensitive customer data from the network using insecure protocols. Which action prevents this type of attack in the future?
- A. Use syslog to gather data from multiple sources and detect intrusion logs for timely responses
- B. Deploy a SOAR solution and correlate log alerts from customer zones
- C. Deploy IDS within sensitive areas and continuously update signatures
- D. Use VLANs to segregate zones and the firewall to allow only required services and secured protocols
Answer: D
NEW QUESTION 38
......
Dumps Moneyack Guarantee - 350-201 Dumps Approved Dumps: https://actualtests.realvalidexam.com/350-201-real-exam-dumps.html
