exam questions

Exam 210-250 All Questions

View all questions & answers for the 210-250 exam

Exam 210-250 topic 1 question 261 discussion

Actual exam question from Cisco's 210-250
Question #: 261
Topic #: 1
[All 210-250 Questions]

Which two methods might be used by an analyst to detect SSL/TLS encrypted command-and-control communication? (Choose two.)

  • A. perform decryption and inspection of SSL/TLS traffic
  • B. perform firewall HTTP application inspection to detect for the command and control traffic
  • C. perform IPS HTTP deep packets inspection to detect for the command and control traffic
  • D. perform analysis of the NetFlow data to detect anomalous TLS/SSL flows
Show Suggested Answer Hide Answer
Suggested Answer: AD 🗳️
The correct answers are "perform decryption and inspection of SSL/TLS traffic" and "perform analysis of the Netflow data to detect anomalous TLS/SSL flows."

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
kelvinOng
4 years, 2 months ago
how can it be A? How analysis decrypt and inspect the encryption traffic?
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago