{"id":14460,"date":"2026-09-17T05:11:59","date_gmt":"2026-09-17T05:11:59","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=14460"},"modified":"2026-09-17T05:11:59","modified_gmt":"2026-09-17T05:11:59","slug":"cisco-200-201-practice-test-questions-and-exam-dumps-part2-q21-40","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-200-201-practice-test-questions-and-exam-dumps-part2-q21-40\/","title":{"rendered":"Cisco 200-201 Practice Test Questions and Exam Dumps Part2 Q21-40"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"http:\/\/examlabs.com\/200-201-exam-dumps\"><b>Cisco 200-201 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 21<\/b><\/h3>\n<p><b>Which protocol is commonly used to collect management and monitoring information from network devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SMTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SSH<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Simple Network Management Protocol (SNMP) is widely used to monitor and manage network devices such as routers, switches, firewalls, and servers. SNMP can collect information about interfaces, CPU utilization, memory usage, device availability, and other operational metrics. Network management systems can use SNMP polling and notifications to identify potential problems. SMTP is used for email transmission, FTP is designed for file transfer, and SSH provides secure remote management. SNMP versions differ in their security capabilities, with SNMPv3 providing authentication and encryption features. Therefore, SNMP is the appropriate protocol for collecting network-management information.<\/span><\/p>\n<h3><b>Question 22<\/b><\/h3>\n<p><b>Which attack technique uses deceptive phone calls to persuade victims to reveal sensitive information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vishing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pharming<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tailgating<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dumpster diving<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Vishing, or voice phishing, is a social engineering technique that uses telephone calls or voice communications to deceive victims. Attackers may impersonate banks, technical-support personnel, government agencies, or company employees and attempt to obtain passwords, financial information, authentication codes, or other sensitive data. Pharming redirects users to fraudulent websites, tailgating involves physically following an authorized person into a restricted area, and dumpster diving involves searching discarded materials for useful information. Organizations can reduce vishing risks through security awareness training and procedures for independently verifying unexpected requests. Therefore, vishing is the correct answer.<\/span><\/p>\n<h3><b>Question 23<\/b><\/h3>\n<p><b>Which security control can prevent unauthorized users from accessing a network by requiring identity verification before granting access?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Address Translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Authentication verifies the identity of a user, device, or system before access is granted. It can use passwords, certificates, tokens, biometrics, or combinations of these methods. Authentication is a fundamental component of access control because security systems need to establish who or what is requesting access before authorization decisions can be applied. Network Address Translation changes addressing information, data compression reduces data size, and load balancing distributes workloads across systems. Authentication should also be combined with authorization and accounting controls for a comprehensive access-control process. Therefore, authentication is the correct security control.<\/span><\/p>\n<h3><b>Question 24<\/b><\/h3>\n<p><b>Which Cisco technology provides centralized visibility into network traffic and can help detect suspicious behavior using flow-based telemetry?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Identity Services Engine<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Secure Endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Secure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Secure Network Analytics<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Cisco Secure Network Analytics provides network visibility and security analytics using telemetry such as network-flow information. It can help security teams identify unusual traffic patterns, suspicious communications, and potential threats across network environments. Cisco Identity Services Engine focuses on identity-based access control, Cisco Secure Endpoint protects endpoint systems, and Cisco Secure Firewall provides network security and traffic-control capabilities. Network analytics is particularly useful for detecting abnormal behavior that may not be obvious from traditional perimeter controls. Therefore, Cisco Secure Network Analytics is the technology most closely associated with flow-based network visibility and behavioral analysis.<\/span><\/p>\n<h3><b>Question 25<\/b><\/h3>\n<p><b>Which type of malware is designed to secretly monitor a user&#8217;s activities and collect information without their knowledge?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Spyware<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ransomware<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Worm<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Spyware is malicious software designed to monitor user activity and collect information without the user&#8217;s informed consent. Depending on its capabilities, spyware may capture browsing activity, credentials, keystrokes, or other sensitive information. Ransomware primarily attempts to deny access to data or systems, while worms are designed to self-propagate across systems or networks. A firewall is a security control rather than malware. Endpoint protection, application controls, security awareness, and regular software updates can help reduce exposure to spyware. Therefore, spyware is the malware category that specifically focuses on covert monitoring and information collection.<\/span><\/p>\n<h3><b>Question 26<\/b><\/h3>\n<p><b>Which network attack attempts to insert malicious traffic between a legitimate user and a destination by exploiting weaknesses in address resolution?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password spraying<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP spoofing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Brute-force authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data destruction<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">ARP spoofing involves sending forged Address Resolution Protocol messages to associate an attacker&#8217;s MAC address with the IP address of another device, such as a gateway. This can allow the attacker to intercept traffic and potentially perform a man-in-the-middle attack. Security mechanisms such as Dynamic ARP Inspection can help protect switched networks from certain ARP spoofing attacks. Password spraying targets authentication systems, brute-force attacks attempt many credential combinations, and data destruction focuses on damaging or deleting information. Therefore, ARP spoofing is the technique associated with manipulating address-resolution information to intercept network traffic.<\/span><\/p>\n<h3><b>Question 27<\/b><\/h3>\n<p><b>Which security solution is primarily designed to protect endpoints from malware, exploit attempts, and other malicious activity?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Secure Endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Secure Network Analytics<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Identity Services Engine<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Secure Firewall<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Cisco Secure Endpoint is designed to provide endpoint protection against malicious activity. Endpoint security solutions can monitor processes and files, identify suspicious behavior, detect malware, and support response actions when threats are discovered. Cisco Secure Network Analytics focuses on network visibility and behavioral analytics, Identity Services Engine provides identity-based network access control, and Secure Firewall provides network traffic security. Endpoint protection is important because attacks can originate from compromised workstations, laptops, and servers even when perimeter security controls are in place. Therefore, Cisco Secure Endpoint is the most appropriate solution for endpoint-focused threat protection.<\/span><\/p>\n<h3><b>Question 28<\/b><\/h3>\n<p><b>Which authentication protocol is commonly associated with centralized authentication and authorization for network access using a client-server model?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TFTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ICMP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">RADIUS is an authentication, authorization, and accounting protocol commonly used for centralized access control. Network devices can forward authentication requests to a RADIUS server rather than maintaining separate credentials locally. RADIUS is frequently used with technologies such as wireless authentication and network access control. TFTP provides simple file transfer, ICMP supports network diagnostic and control functions, and DNS resolves names to addresses. Centralized authentication improves administration because organizations can manage access policies and user credentials through a central service. Therefore, RADIUS is the appropriate protocol for centralized network-access authentication and authorization.<\/span><\/p>\n<h3><b>Question 29<\/b><\/h3>\n<p><b>Which security principle protects sensitive information from being disclosed to unauthorized individuals?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Availability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Integrity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Confidentiality<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Scalability<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Confidentiality is the security principle concerned with preventing unauthorized disclosure of information. Access controls, encryption, authentication, data classification, and permissions are commonly used to protect confidential information. Integrity focuses on preventing or detecting unauthorized modification, while availability ensures that authorized users can access systems and information when required. Scalability is a design characteristic rather than one of the core information-security principles. Organizations often use the CIA triad\u2014confidentiality, integrity, and availability\u2014to describe fundamental security objectives. Therefore, confidentiality is the correct principle when the primary concern is preventing unauthorized disclosure.<\/span><\/p>\n<h3><b>Question 30<\/b><\/h3>\n<p><b>Which attack attempts to use a small number of commonly used passwords against many different user accounts?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential theft<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password spraying<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet sniffing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Password spraying is an attack technique in which an attacker tries a small number of commonly used passwords against many different accounts. Unlike traditional brute-force attacks, which may attempt many passwords against one account, password spraying attempts to avoid account lockout thresholds by distributing authentication attempts across multiple accounts. Credential theft refers to obtaining credentials through various methods, SQL injection targets vulnerable applications and databases, and packet sniffing involves capturing network traffic. Strong password policies, multifactor authentication, monitoring, and account-protection mechanisms can reduce password-spraying risk. Therefore, password spraying is the correct answer.<\/span><\/p>\n<h3><b>Question 31<\/b><\/h3>\n<p><b>Which protocol provides encrypted remote terminal access to a network device?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SSH<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Telnet<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HTTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">SSH provides secure, encrypted remote command-line access to network devices and servers. It protects authentication credentials and management traffic while communicating across an untrusted network. Telnet also provides remote terminal access but transmits information without the same encryption protection. HTTP is primarily used for web communication, while SNMP is mainly used for network monitoring and management. Network administrators commonly use SSH when remotely configuring Cisco devices because protecting management credentials and configuration information is important. Therefore, SSH is the appropriate protocol for encrypted remote terminal access.<\/span><\/p>\n<h3><b>Question 32<\/b><\/h3>\n<p><b>Which type of attack attempts to exploit a vulnerability in an application by inserting malicious database commands into user-supplied input?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP spoofing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DDoS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Phishing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">SQL injection is an application-layer attack in which malicious SQL statements or fragments are inserted into input fields or other application parameters. If an application fails to properly validate and handle input, an attacker may manipulate database queries and potentially access, modify, or delete data. Secure coding practices, parameterized queries, input validation, and appropriate database permissions can help prevent SQL injection. ARP spoofing targets local network address resolution, DDoS attacks target service availability, and phishing uses social engineering. Therefore, SQL injection is the attack associated with malicious database commands inserted through application input.<\/span><\/p>\n<h3><b>Question 33<\/b><\/h3>\n<p><b>Which security mechanism can use digital certificates to verify the identity of a server or user?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public Key Infrastructure<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Address Translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic Host Configuration Protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Spanning Tree Protocol<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Public Key Infrastructure, or PKI, provides the framework for using digital certificates and public-key cryptography to establish trust and verify identities. Certificate authorities issue and manage certificates that can be used to authenticate servers, users, and devices. PKI is commonly associated with secure web communication, VPN authentication, device identity, and other security applications. NAT translates network addresses, DHCP provides network configuration information, and STP prevents switching loops. PKI can also support encryption and digital signatures depending on how certificates and keys are used. Therefore, Public Key Infrastructure is the correct answer.<\/span><\/p>\n<h3><b>Question 34<\/b><\/h3>\n<p><b>Which network security control can prevent a compromised endpoint from communicating with known malicious destinations?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS caching<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security policy enforcement<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network time synchronization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Security policy enforcement can prevent or restrict communication between compromised endpoints and known malicious destinations. Depending on the architecture, this can be implemented through firewalls, security gateways, endpoint controls, DNS security, or other filtering technologies. Such controls can block malicious IP addresses, domains, applications, or communication patterns. DNS caching improves name-resolution performance, time synchronization ensures consistent device clocks, and file compression reduces storage or transmission size. Effective security policies should be regularly updated as threat intelligence and organizational requirements change. Therefore, security policy enforcement is the appropriate control for restricting malicious communications.<\/span><\/p>\n<h3><b>Question 35<\/b><\/h3>\n<p><b>Which technology is commonly used to provide secure access to a private network over an untrusted public network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A Virtual Private Network, or VPN, creates a protected communication channel across an untrusted network such as the public Internet. VPN technologies can use encryption, authentication, and tunneling to protect data between endpoints or networks. Organizations commonly use VPNs for remote-access connectivity and secure connections between geographically separated offices. DHCP dynamically provides IP configuration, NAT translates addresses, and FTP provides file-transfer functionality. The exact security characteristics of a VPN depend on the tunneling and cryptographic technologies used. Therefore, VPN is the technology commonly used to securely connect to private network resources over an untrusted network.<\/span><\/p>\n<h3><b>Question 36<\/b><\/h3>\n<p><b>Which type of security control is intended to restore systems and data after a security incident or hardware failure?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Preventive control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Detective control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Corrective control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deterrent control<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Corrective controls are designed to reduce the impact of an incident and restore systems or operations after an unwanted event has occurred. Examples include restoring data from backups, rebuilding compromised systems, and applying corrective configurations after an incident. Preventive controls attempt to stop incidents before they occur, detective controls identify or alert on suspicious activity, and deterrent controls are intended to discourage unwanted behavior. A well-designed security program uses multiple control types because no single control can address every threat. Therefore, corrective control is the appropriate category for controls focused on recovery after an incident.<\/span><\/p>\n<h3><b>Question 37<\/b><\/h3>\n<p><b>Which protocol is commonly used to securely transfer email between mail servers?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HTTPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SMTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SSH<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SFTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">SMTP, or Simple Mail Transfer Protocol, is the standard protocol used for transferring email between mail systems. Secure email transport can use SMTP with TLS to encrypt the communication channel between participating servers. HTTPS is used for secure web communication, SSH provides secure remote administration, and SFTP provides secure file transfer over SSH. SMTP is specifically associated with sending and relaying email, while protocols such as IMAP and POP3 are commonly used for retrieving email. Therefore, SMTP is the appropriate protocol for transferring email between mail servers, with TLS providing additional transport security when configured.<\/span><\/p>\n<h3><b>Question 38<\/b><\/h3>\n<p><b>Which attack involves an attacker sending a large number of authentication attempts using credentials obtained from previous data breaches?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential stuffing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN hopping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Smurf attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS tunneling<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Credential stuffing uses previously compromised username and password combinations to attempt authentication against other online services. The attack takes advantage of password reuse, where users use the same credentials across multiple systems. Multifactor authentication, unique passwords, password managers, breached-password detection, and login monitoring can reduce the effectiveness of credential stuffing. VLAN hopping attempts to bypass network segmentation, Smurf attacks involve amplified ICMP traffic, and DNS tunneling can use DNS queries to transport data. Therefore, credential stuffing is the attack specifically associated with reusing stolen credentials from previous breaches.<\/span><\/p>\n<h3><b>Question 39<\/b><\/h3>\n<p><b>Which technology can provide centralized collection of security and system log messages from network devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Syslog<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Syslog is commonly used to collect and centralize log messages generated by network devices, servers, applications, and security systems. A centralized syslog server allows administrators and security teams to review events from multiple systems in one location. Centralized logging supports troubleshooting, monitoring, incident investigation, and event correlation. SNMP is primarily used for device monitoring and management, DHCP provides IP configuration, and NTP synchronizes system clocks. Accurate time synchronization is particularly useful when analyzing centralized logs because timestamps from different devices can be correlated more reliably. Therefore, Syslog is the correct technology for centralized log collection.<\/span><\/p>\n<h3><b>Question 40<\/b><\/h3>\n<p><b>Which security approach uses multiple independent security controls so that failure of one control does not necessarily expose the entire environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single sign-on<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data minimization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Defense in depth uses multiple layers of security controls to protect systems and information. These layers may include firewalls, endpoint protection, authentication, network segmentation, monitoring, encryption, access controls, and security awareness. If one security mechanism fails or is bypassed, additional controls may still detect or prevent the attack. Single sign-on simplifies authentication across applications, least privilege limits permissions to what is required, and data minimization reduces unnecessary data collection or retention. Therefore, defense in depth is the security approach that relies on multiple independent protective layers.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco 200-201 Exam Dumps and Practice Test Dumps. &nbsp; Question 21 Which protocol is commonly used to collect management and monitoring information from network devices? SMTP SNMP FTP SSH Correct Answer: 2 Explanation Simple Network Management Protocol (SNMP) is widely used to monitor and manage network devices such as routers, switches, firewalls, and [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14460"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=14460"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14460\/revisions"}],"predecessor-version":[{"id":14501,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14460\/revisions\/14501"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=14460"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=14460"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=14460"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}