exam questions

Exam 200-201 All Questions

View all questions & answers for the 200-201 exam

Exam 200-201 topic 1 question 117 discussion

Actual exam question from Cisco's 200-201
Question #: 117
Topic #: 1
[All 200-201 Questions]

DRAG DROP -
Drag and drop the type of evidence from the left onto the description of that evidence on the right.
Select and Place:

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Mevijil
Highly Voted 1 year, 9 months ago
I'm pretty sure it should be: -C2 Log = Best -Firewall Log = Corroborative -Netflow = Indirect The C2 log seems to be direct evidence of a crime, while the firewall log seems to be corroborating that 'something' is happening, while the netflow spike is only circumstantial (could be indicative of something else happening, could not be).
upvoted 15 times
bn1234
1 year, 8 months ago
Agreed
upvoted 5 times
...
...
drdecker100
Most Recent 9 months, 3 weeks ago
Overall, the combination of these three pieces of evidence could be used to build a stronger case that there is malware present on the system and that it is communicating with a command and control server. The direct evidence of the malware check-in is supported by the corroborative evidence of the successful communication with a known malware-hosting IP address, while the indirect evidence of the netflow-based spike in DNS traffic provides additional context that further supports the presence of suspicious activity on the network.
upvoted 3 times
...
Eng_ahmedyoussef
1 year, 2 months ago
Direct - indirect - corroborative
upvoted 3 times
...
DLukynskyy
1 year, 8 months ago
corroborative based on next question
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...