{"id":14463,"date":"2026-09-17T05:10:50","date_gmt":"2026-09-17T05:10:50","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=14463"},"modified":"2026-09-17T05:10:51","modified_gmt":"2026-09-17T05:10:51","slug":"cisco-200-201-practice-test-questions-and-exam-dumps-part5-q81-100","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-200-201-practice-test-questions-and-exam-dumps-part5-q81-100\/","title":{"rendered":"Cisco 200-201 Practice Test Questions and Exam Dumps Part5 Q81-100"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"http:\/\/examlabs.com\/200-201-exam-dumps\"><b>Cisco 200-201 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 81<\/b><\/h3>\n<p><b>Which email security technology uses cryptographic signatures to help verify that an email message has not been modified after being sent?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SPF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DKIM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">DomainKeys Identified Mail, or DKIM, uses cryptographic signatures to associate an email message with a sending domain and help verify message integrity. The sending mail server signs selected parts of the message using a private key. The receiving server can retrieve the corresponding public key from DNS and validate the signature. If signed content has been altered, verification may fail. SPF focuses on whether a sending server is authorized for a domain, while DMARC provides policy and reporting using authentication mechanisms such as SPF and DKIM. DHCP and FTP do not provide email authentication. Therefore, DKIM is correct.<\/span><\/p>\n<h3><b>Question 82<\/b><\/h3>\n<p><b>Which email security standard allows domain owners to specify how receiving systems should handle messages that fail authentication checks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DMARC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SFTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Domain-based Message Authentication, Reporting, and Conformance, or DMARC, allows domain owners to publish policies describing how receiving mail systems should handle messages that fail authentication requirements. DMARC can use SPF and DKIM results along with domain alignment checks. Organizations can configure policies that request monitoring, quarantine, or rejection of messages that fail the required checks. DMARC also supports reporting, helping domain administrators identify potential spoofing and authentication problems. SFTP, SNMP, and NTP perform unrelated functions. Therefore, DMARC is the correct technology for defining email authentication handling policies.<\/span><\/p>\n<h3><b>Question 83<\/b><\/h3>\n<p><b>Which malware type is designed to secretly provide unauthorized privileged access to a compromised system?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Worm<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rootkit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Adware<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Spam<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A rootkit is a type of malicious software designed to maintain unauthorized access while hiding its presence from users and security tools. Rootkits may operate at different levels of a system and can attempt to conceal malicious processes, files, network connections, or other activity. Because they are designed for stealth and persistence, detecting them can be challenging. Worms primarily spread automatically between systems, adware displays unwanted advertising, and spam refers to unsolicited messages rather than a specific malware type. Endpoint monitoring, secure configurations, patching, and integrity checking can help reduce rootkit-related risks. Therefore, rootkit is correct.<\/span><\/p>\n<h3><b>Question 84<\/b><\/h3>\n<p><b>Which malware characteristic allows a malicious program to spread automatically from one vulnerable system to another?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Persistence<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Self-propagation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Self-propagation is a characteristic commonly associated with computer worms. A worm can exploit vulnerabilities, weak credentials, or other mechanisms to spread from one system to another without requiring the user to manually execute the malware on every target. This ability can allow infections to spread rapidly across networks. Encryption protects information from unauthorized access, persistence describes the ability of malware to remain active after reboot or other events, and authentication verifies identity. Network segmentation, patch management, endpoint security, and vulnerability remediation can reduce the opportunities available for automated propagation. Therefore, self-propagation is correct.<\/span><\/p>\n<h3><b>Question 85<\/b><\/h3>\n<p><b>Which attack attempts to redirect users from a legitimate website to a malicious destination by manipulating DNS information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS spoofing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password spraying<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MAC flooding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shoulder surfing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">DNS spoofing involves providing fraudulent DNS information so that users or applications resolve a legitimate domain name to an incorrect IP address. This can redirect victims toward malicious websites or services controlled by an attacker. DNS cache poisoning is one method through which false DNS information can be introduced into a resolver&#8217;s cache. Security mechanisms such as DNSSEC validation can help protect DNS integrity. Password spraying targets authentication systems, MAC flooding targets switch CAM tables, and shoulder surfing involves observing sensitive information directly. Therefore, DNS spoofing is the correct attack.<\/span><\/p>\n<h3><b>Question 86<\/b><\/h3>\n<p><b>Which type of attack attempts to steal an authenticated user&#8217;s active session and use it to access a service?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN hopping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Session hijacking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP starvation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS tunneling<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Session hijacking occurs when an attacker obtains or takes control of an authenticated user&#8217;s active session. If the attacker can acquire a valid session token or otherwise impersonate the established session, the service may treat the attacker as the legitimate user. Secure transport such as HTTPS, protected session cookies, appropriate session expiration, multifactor authentication, and secure application design can reduce this risk. VLAN hopping targets network segmentation, DHCP starvation exhausts address pools, and DNS tunneling can use DNS communications to transfer information or establish covert communication. Therefore, session hijacking is correct.<\/span><\/p>\n<h3><b>Question 87<\/b><\/h3>\n<p><b>Which attack technique involves compromising a legitimate website that members of a particular organization are likely to visit?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Watering-hole attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Brute-force attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Smurf attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential stuffing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A watering-hole attack compromises or manipulates a website that a targeted group is known to visit. Instead of directly attacking every intended victim, the attacker places malicious content or exploits on a trusted website and waits for members of the target group to access it. This technique can be effective when attackers have information about their target&#8217;s browsing habits. Brute-force attacks attempt many credential combinations, credential stuffing uses previously stolen credentials, and Smurf attacks are denial-of-service attacks involving ICMP traffic amplification. Therefore, a watering-hole attack is the correct answer.<\/span><\/p>\n<h3><b>Question 88<\/b><\/h3>\n<p><b>Which attack attempts to exploit a web application by inserting malicious database commands into user-supplied input?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP spoofing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MAC flooding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP starvation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">SQL injection occurs when an application improperly handles user-supplied input and allows an attacker to manipulate database queries. Successful SQL injection can potentially expose, modify, or delete database information, depending on application privileges and database configuration. Secure coding practices such as parameterized queries, prepared statements, input validation, and appropriate database permissions help reduce this risk. ARP spoofing targets local network address resolution, MAC flooding targets switch forwarding tables, and DHCP starvation attempts to exhaust IP address assignments. Therefore, SQL injection is the attack involving malicious database commands inserted through application input.<\/span><\/p>\n<h3><b>Question 89<\/b><\/h3>\n<p><b>Which attack uses many compromised devices to generate traffic against a target simultaneously?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DDoS attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNSSEC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate validation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A Distributed Denial-of-Service, or DDoS, attack uses multiple systems, often a botnet or other collection of compromised devices, to send large volumes of traffic or requests toward a target. The objective is generally to consume network bandwidth, server resources, application capacity, or other resources and reduce service availability. DDoS attacks can be difficult to mitigate because traffic originates from many sources. DNSSEC protects DNS integrity, port security controls switch access, and certificate validation helps establish trust in digital certificates. Therefore, a DDoS attack is the correct answer.<\/span><\/p>\n<h3><b>Question 90<\/b><\/h3>\n<p><b>Which security activity systematically identifies known vulnerabilities in systems and applications?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet forwarding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Vulnerability scanning uses automated tools to examine systems, applications, network services, and configurations for known security weaknesses. Scanners may compare detected software versions or configurations against vulnerability databases and security checks. Organizations can then prioritize identified issues according to factors such as severity, exposure, and business impact. Vulnerability scanning differs from penetration testing because scanning generally focuses on identifying potential weaknesses, while penetration testing involves controlled attempts to exploit vulnerabilities. Encryption protects confidentiality, packet forwarding moves network traffic, and compression reduces data size. Therefore, vulnerability scanning is the correct activity.<\/span><\/p>\n<h3><b>Question 91<\/b><\/h3>\n<p><b>Which vulnerability scoring system commonly uses a numerical scale to communicate the severity of software vulnerabilities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CVSS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SMTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">The Common Vulnerability Scoring System, or CVSS, provides a standardized framework for describing and scoring the severity of security vulnerabilities. CVSS metrics consider characteristics such as attack complexity, privileges required, user interaction, and the potential impact on confidentiality, integrity, and availability. Organizations can use these scores as one factor when prioritizing vulnerability remediation. CVSS does not itself fix vulnerabilities or determine the complete business risk of an issue. DNS resolves names, DHCP provides network configuration, and SMTP transports email. Therefore, CVSS is the correct vulnerability severity scoring system.<\/span><\/p>\n<h3><b>Question 92<\/b><\/h3>\n<p><b>Which activity differs from vulnerability scanning because it attempts to actively exploit identified weaknesses in a controlled manner?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset inventory<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Penetration testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log collection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Penetration testing is an authorized security assessment in which testers attempt to exploit vulnerabilities under controlled conditions. The purpose is to determine whether identified weaknesses can actually be exploited and to understand their potential impact. Penetration testing normally follows defined rules of engagement to prevent unnecessary disruption to production systems. Vulnerability scanning generally identifies potential weaknesses without necessarily exploiting them. Asset inventory identifies systems and devices, log collection gathers security events, and data classification categorizes information. Therefore, penetration testing is the activity that actively tests weaknesses in a controlled manner.<\/span><\/p>\n<h3><b>Question 93<\/b><\/h3>\n<p><b>Which security monitoring technology commonly collects and correlates logs from multiple systems to identify suspicious activity?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RAID<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A Security Information and Event Management, or SIEM, platform collects security-related logs and events from multiple sources and can correlate them to identify suspicious patterns. Sources may include firewalls, servers, endpoints, authentication systems, applications, and network devices. Centralized analysis can help security teams investigate incidents and identify relationships that might be difficult to recognize when reviewing individual logs separately. NAT translates addresses, RAID provides storage redundancy, and VLANs logically separate network segments. Therefore, SIEM is the technology commonly used to centralize and correlate security events.<\/span><\/p>\n<h3><b>Question 94<\/b><\/h3>\n<p><b>Which network-flow technology provides information about communication patterns without necessarily capturing the complete contents of every packet?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NetFlow<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Telnet<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">NetFlow provides metadata about network traffic flows rather than requiring complete packet-content capture. Information can include source and destination addresses, ports, protocols, packet counts, byte counts, and timing information. Security teams can use flow information to identify unusual communication patterns, large transfers, scanning behavior, and other anomalies. Full packet capture provides significantly more content but generally requires greater storage and processing resources. FTP transfers files, Telnet provides insecure remote access, and DHCP provides IP configuration. Therefore, NetFlow is the appropriate technology for monitoring network communication patterns through flow metadata.<\/span><\/p>\n<h3><b>Question 95<\/b><\/h3>\n<p><b>Which incident response phase focuses on stopping the spread of an active security incident?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Recovery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Containment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Lessons learned<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Containment is the incident response phase focused on limiting the scope and impact of an active security incident. Security teams may isolate compromised endpoints, block malicious traffic, disable affected accounts, or segment portions of the network. The exact action depends on the incident and organizational procedures. Identification focuses on determining whether an incident has occurred and understanding its characteristics. Recovery focuses on restoring affected systems to normal operation, while lessons learned evaluates the incident afterward to improve future response. Therefore, containment is the phase primarily concerned with stopping or limiting the spread of an incident.<\/span><\/p>\n<h3><b>Question 96<\/b><\/h3>\n<p><b>Which incident response phase involves restoring affected systems and services to normal operation after a security incident?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Recovery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Containment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Detection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Preparation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Recovery focuses on restoring systems, applications, and services after an incident has been contained and addressed. Activities can include rebuilding compromised systems, restoring verified backups, removing malicious components, validating system security, and returning services to normal operation. Recovery should be performed carefully to avoid reintroducing compromised files or configurations. Preparation occurs before incidents and involves establishing policies, tools, and procedures. Detection identifies suspicious activity, while containment limits the incident&#8217;s spread. Therefore, recovery is the incident response phase associated with restoring affected systems and services.<\/span><\/p>\n<h3><b>Question 97<\/b><\/h3>\n<p><b>Which security principle requires granting users only the permissions necessary to perform their assigned tasks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">High availability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data replication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">The principle of least privilege means users, applications, and systems should receive only the permissions required to perform legitimate tasks. Limiting privileges reduces the potential damage if an account or application is compromised. For example, a standard employee account generally should not have unnecessary administrative privileges. Least privilege can be implemented through role-based access control, separate administrator accounts, permission reviews, and carefully designed authorization policies. Defense in depth uses multiple security layers, high availability focuses on service uptime, and data replication maintains copies of information. Therefore, least privilege is the correct principle.<\/span><\/p>\n<h3><b>Question 98<\/b><\/h3>\n<p><b>Which security architecture places publicly accessible services in a separate network segment from an organization&#8217;s internal network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DMZ<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Loopback<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RAID<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT pool<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A demilitarized zone, or DMZ, is a network segment designed to host services that need to be reachable from less-trusted networks, such as the Internet. Common examples include public web servers, mail gateways, and DNS servers. Placing these systems in a separate segment can limit the direct exposure of internal resources if a public-facing server is compromised. Firewalls and access-control policies are typically used to control traffic between the Internet, DMZ, and internal network. Loopback addresses are local host addresses, RAID concerns storage, and NAT pools are used for address translation. Therefore, DMZ is correct.<\/span><\/p>\n<h3><b>Question 99<\/b><\/h3>\n<p><b>Which security approach uses multiple independent protective mechanisms so that failure of one control does not necessarily expose the entire environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single sign-on<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat networking<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Defense in depth uses multiple layers of security controls rather than depending on a single mechanism. An organization may combine firewalls, endpoint protection, multifactor authentication, network segmentation, access controls, monitoring, encryption, and security awareness training. If one control fails or is bypassed, additional controls may still prevent or detect the attack. This layered approach can reduce the likelihood that one security failure will result in complete compromise. Single sign-on simplifies authentication, open authentication provides little protection, and flat networking reduces segmentation. Therefore, defense in depth is the correct security approach.<\/span><\/p>\n<h3><b>Question 100<\/b><\/h3>\n<p><b>Which protocol should be avoided for secure remote device administration because it transmits credentials and session data without encryption?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SSH<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HTTPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Telnet<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SFTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Telnet provides remote terminal access but does not encrypt the communication between the client and server. As a result, usernames, passwords, commands, and other session information can potentially be intercepted by an attacker with access to the communication path. SSH is the preferred secure alternative because it encrypts remote administration sessions. HTTPS protects web communications, while SFTP provides secure file transfer through SSH. Organizations should disable Telnet where possible and use secure protocols for administrative access. Therefore, Telnet is the protocol that should be avoided for secure remote device administration.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco 200-201 Exam Dumps and Practice Test Dumps. &nbsp; Question 81 Which email security technology uses cryptographic signatures to help verify that an email message has not been modified after being sent? SPF DHCP DKIM FTP Correct Answer: 3 Explanation DomainKeys Identified Mail, or DKIM, uses cryptographic signatures to associate an email message [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14463"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=14463"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14463\/revisions"}],"predecessor-version":[{"id":14498,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14463\/revisions\/14498"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=14463"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=14463"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=14463"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}