Want to pass your Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS) 200-201 exam in the very first attempt? Try Pass2lead! It is equally effective for both starters and IT professionals.
VCE
What is a collection of compromised machines that attackers use to carry out a DDoS attack?
A. subnet
B. botnet
C. VLAN
D. command and control
A SOC analyst detected connections to known CandC and port scanning activity to main HR database servers from one of the HR endpoints, via Cisco StealthWatch. What are the two next steps of the SOC team according to the NIST.SP80061 incident handling process? (Choose two.)
A. Update antivirus signature databases on affected endpoints to block connections to CandC.
B. Isolate affected endpoints and take disk images for analysis.
C. Block connection to this CandC server on the perimeter next-generation firewall.
D. Provide security awareness training to HR managers and employees
E. Detect the attack vector and analyze CandC connections.
A CMS plugin creates two files that are accessible from the Internet: myplugin.html and exploitable.php. A newly discovered exploit takes advantage of an injection vulnerability in exploitable.php. To exploit the vulnerability, an HTTP POST must be sent with specific variables to exploitable.php. A security engineer notices traffic to the webserver that consists of only HTTP GET requests to myplugin.html. Which category does this activity fall under?
A. exploitation
B. reconnaissance
C. installation
D. weaponization