{"id":14471,"date":"2026-09-17T05:08:59","date_gmt":"2026-09-17T05:08:59","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=14471"},"modified":"2026-09-17T05:08:59","modified_gmt":"2026-09-17T05:08:59","slug":"cisco-200-201-practice-test-questions-and-exam-dumps-part13-q241-260","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-200-201-practice-test-questions-and-exam-dumps-part13-q241-260\/","title":{"rendered":"Cisco 200-201 Practice Test Questions and Exam Dumps Part13 Q241-260"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"http:\/\/examlabs.com\/200-201-exam-dumps\"><b>Cisco 200-201 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 241<\/b><\/h3>\n<p><b>Which security control provides a centralized method for collecting security events from firewalls, servers, and endpoints?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A Security Information and Event Management system, or SIEM, provides centralized collection and analysis of security events from many sources. These sources can include firewalls, servers, endpoints, applications, authentication systems, and network devices. Centralizing events allows security teams to correlate information and identify suspicious patterns that might not be visible when reviewing individual devices separately. SIEM platforms can also generate alerts, support investigations, and provide reporting capabilities. NAT translates addresses, DHCP provides network configuration, and DNS resolves domain names. Therefore, SIEM is the appropriate technology for centralized security-event collection and analysis.<\/span><\/p>\n<h3><b>Question 242<\/b><\/h3>\n<p><b>Which security principle ensures that users receive only the permissions required to perform their assigned responsibilities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Maximum privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">The principle of least privilege requires users, applications, and devices to receive only the permissions necessary to perform their legitimate tasks. Limiting privileges reduces the potential impact of compromised accounts, malware, and accidental actions. For example, a regular employee should not automatically receive administrator privileges on servers that are unrelated to their responsibilities. Least privilege should also be reviewed regularly because users&#8217; roles and responsibilities can change over time. Open access and maximum privilege increase exposure, while shared administration can reduce accountability. Therefore, least privilege is the correct security principle.<\/span><\/p>\n<h3><b>Question 243<\/b><\/h3>\n<p><b>Which protocol provides encrypted communication for securely transferring files between systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TFTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SFTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HTTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Secure File Transfer Protocol, commonly called SFTP, provides secure file transfers using the SSH protocol. It encrypts authentication information and file data during transmission, helping protect sensitive information from interception. SFTP is commonly used by administrators and organizations to securely transfer configuration files, reports, backups, and other data. Traditional FTP does not encrypt information by default, while TFTP provides basic file transfer without strong security features. HTTP is primarily designed for web communication. Therefore, SFTP is the appropriate protocol when secure file transfer is required.<\/span><\/p>\n<h3><b>Question 244<\/b><\/h3>\n<p><b>Which technology can authenticate users centrally before granting access to network resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RAID<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">RADIUS is a widely used protocol for centralized authentication, authorization, and accounting. Network devices such as wireless controllers, switches, and VPN gateways can communicate with a RADIUS server to validate user credentials and apply access policies. RADIUS is commonly used with 802.1X network access control and enterprise wireless authentication. RAID provides storage redundancy, NAT translates network addresses, and NTP synchronizes system clocks. Centralized authentication allows administrators to manage access policies from a common authentication infrastructure instead of maintaining separate credentials on every network device. Therefore, RADIUS is correct.<\/span><\/p>\n<h3><b>Question 245<\/b><\/h3>\n<p><b>Which attack attempts to trick a user into visiting a malicious website by compromising a legitimate website frequently visited by the target group?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Watering-hole attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Brute-force attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP starvation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MAC flooding<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A watering-hole attack compromises or manipulates a legitimate website that members of a particular target group are likely to visit. When targeted users access the compromised site, attackers may attempt to exploit browser vulnerabilities, deliver malware, or redirect users to malicious resources. The attack relies on the victim&#8217;s trust in the legitimate website rather than directly sending a deceptive message. Brute-force attacks attempt repeated credential guesses, DHCP starvation exhausts address pools, and MAC flooding targets switch CAM tables. Therefore, a watering-hole attack is the technique described.<\/span><\/p>\n<h3><b>Question 246<\/b><\/h3>\n<p><b>Which security technology can detect suspicious activity on an endpoint and provide detailed information for investigation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNSSEC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EDR<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Endpoint Detection and Response, or EDR, continuously monitors endpoint activity and collects security telemetry. It can record information about processes, files, network connections, user activity, and other behaviors that may help identify malicious activity. Security teams can use EDR data to investigate incidents, identify affected systems, and perform response actions such as isolating compromised endpoints. NAT translates addresses, DNSSEC protects DNS integrity, and DHCP provides network configuration. EDR is therefore specifically designed to provide endpoint visibility and investigation capabilities.<\/span><\/p>\n<h3><b>Question 247<\/b><\/h3>\n<p><b>Which security mechanism can block access to websites known to contain malware or phishing content?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Web filtering can restrict access to websites based on security reputation, URL categories, domains, or organizational policies. Security teams can use web filtering to block known malicious websites, phishing pages, malware-hosting domains, and other inappropriate resources. Depending on the implementation, filtering can occur through secure web gateways, DNS security services, or other security platforms. NTP synchronizes system clocks, SNMP provides network management, and DHCP assigns network configuration. Web filtering is therefore the security mechanism designed to prevent users from accessing known malicious or restricted web destinations.<\/span><\/p>\n<h3><b>Question 248<\/b><\/h3>\n<p><b>Which security technique replaces sensitive information with a randomly generated substitute that has no direct meaningful value?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hashing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Tokenization replaces sensitive information with a substitute value called a token. The token can be used by applications without exposing the original sensitive information. For example, a payment system may use tokens instead of storing actual payment-card information in multiple systems. Tokenization differs from encryption because the token does not necessarily contain a mathematically reversible representation of the original value. Hashing creates a fixed-length digest, encryption protects data using cryptographic keys, and compression reduces data size. Therefore, tokenization is the correct technique for replacing sensitive information with a substitute value.<\/span><\/p>\n<h3><b>Question 249<\/b><\/h3>\n<p><b>Which attack attempts to steal a user&#8217;s authenticated session by obtaining or predicting the session identifier?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS poisoning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Session hijacking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP starvation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN hopping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Session hijacking occurs when an attacker obtains control of a valid authenticated session, often by stealing or compromising a session identifier or token. If successful, the attacker may be able to act as the legitimate user without knowing the user&#8217;s password. Strong TLS protection, secure session management, short session lifetimes, secure cookies, and additional authentication controls can reduce this risk. DNS poisoning manipulates DNS information, DHCP starvation exhausts address pools, and VLAN hopping attempts to cross VLAN boundaries. Therefore, session hijacking is the attack described.<\/span><\/p>\n<h3><b>Question 250<\/b><\/h3>\n<p><b>Which security technology can provide secure communication between two networks across an untrusted Internet connection?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNSSEC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP snooping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPsec VPN<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">An IPsec VPN can establish an encrypted and authenticated tunnel between networks across an untrusted network such as the public Internet. Site-to-site IPsec VPNs are commonly used to securely connect branch offices, data centers, or other organizational networks. IPsec can provide confidentiality, integrity, authentication, and anti-replay protection depending on its configuration. DNSSEC protects DNS information, DHCP snooping helps defend against certain DHCP attacks, and port security restricts switch-port access. Therefore, an IPsec VPN is the appropriate technology for securely connecting networks over the Internet.<\/span><\/p>\n<h3><b>Question 251<\/b><\/h3>\n<p><b>Which security control helps identify when an important system file has been modified unexpectedly?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File integrity monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Address Translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP snooping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS forwarding<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">File Integrity Monitoring, or FIM, detects changes to important files by comparing their current state with a known trusted baseline. It can monitor characteristics such as cryptographic hashes, file permissions, ownership, and timestamps. Unexpected modifications can indicate malware activity, unauthorized administrative actions, or configuration tampering. FIM is especially useful for monitoring critical operating-system files, application files, and configuration data. NAT translates addresses, DHCP snooping monitors DHCP traffic, and DNS forwarding handles DNS queries. Therefore, file integrity monitoring is the appropriate security control for detecting unauthorized file changes.<\/span><\/p>\n<h3><b>Question 252<\/b><\/h3>\n<p><b>Which attack attempts to gain access by trying a small number of commonly used passwords against many different user accounts?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential stuffing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Brute-force attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password spraying<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Phishing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Password spraying involves trying a small number of commonly used passwords against many different accounts. Attackers use this approach to reduce the likelihood of triggering account-lockout mechanisms that might occur when many passwords are attempted against a single account. Credential stuffing is different because it uses previously compromised username-and-password combinations, while brute-force attacks systematically try many password combinations. Phishing attempts to deceive users into providing credentials or other information. Therefore, password spraying is the attack technique described.<\/span><\/p>\n<h3><b>Question 253<\/b><\/h3>\n<p><b>Which technology can inspect network traffic and actively block malicious connections?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IDS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Syslog<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">An Intrusion Prevention System, or IPS, monitors network traffic and can automatically take action when malicious activity is detected. Depending on its configuration, an IPS can drop packets, block connections, or otherwise prevent identified threats from reaching protected systems. An Intrusion Detection System primarily detects and reports suspicious activity, while a SIEM correlates events from multiple sources. Syslog provides a mechanism for collecting and transporting event messages. Therefore, IPS is the technology capable of both inspecting traffic and actively preventing detected malicious connections.<\/span><\/p>\n<h3><b>Question 254<\/b><\/h3>\n<p><b>Which security process prioritizes vulnerabilities based on factors such as severity, exploitability, and potential impact?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File sharing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Vulnerability management is an ongoing process for identifying, evaluating, prioritizing, remediating, and verifying security weaknesses. Organizations may use vulnerability severity, exploitability, asset importance, exposure, and business impact to determine which vulnerabilities should be addressed first. This approach helps security teams focus limited resources on risks that require the most immediate attention. Network segmentation separates network zones, data compression reduces storage or transmission requirements, and file sharing provides access to files. Therefore, vulnerability management is the correct process for prioritizing and addressing security weaknesses.<\/span><\/p>\n<h3><b>Question 255<\/b><\/h3>\n<p><b>Which protocol is considered insecure for remote command-line administration because it transmits communication without encryption?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SSH<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HTTPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Telnet<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SFTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Telnet provides remote command-line access but does not encrypt the communication by default. Credentials, commands, and other session information can therefore be exposed to attackers who can monitor the communication path. SSH is generally preferred for secure remote administration because it encrypts the session. HTTPS provides encrypted web communication, while SFTP provides secure file transfer over SSH. Replacing Telnet with SSH is an important security improvement when managing network devices or servers across untrusted networks. Therefore, Telnet is the insecure remote-administration protocol described.<\/span><\/p>\n<h3><b>Question 256<\/b><\/h3>\n<p><b>Which security mechanism can prevent unauthorized users from accessing specific applications or files even after successfully authenticating to a system?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authorization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Accounting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encryption<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Authorization determines what an authenticated user is permitted to access or perform. Authentication verifies the identity of the user, but successful authentication does not automatically mean that the user should have access to every resource. Authorization policies can restrict access to specific applications, files, commands, databases, or administrative functions. Accounting records user activity, while encryption protects information from unauthorized disclosure. Separating authentication from authorization allows organizations to provide controlled access according to roles and responsibilities. Therefore, authorization is the correct security mechanism.<\/span><\/p>\n<h3><b>Question 257<\/b><\/h3>\n<p><b>Which security feature helps protect a switch network from unauthorized DHCP servers responding to client requests?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP snooping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNSSEC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPsec<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">DHCP snooping is a switch security feature that helps protect networks from rogue or unauthorized DHCP servers. It classifies switch ports as trusted or untrusted and can block DHCP server messages arriving from unauthorized ports. DHCP snooping can also build trusted IP-to-MAC address bindings that other security features, such as Dynamic ARP Inspection and IP Source Guard, can use. Port security focuses on MAC addresses, DNSSEC protects DNS information, and IPsec secures IP communications. Therefore, DHCP snooping is the correct feature for protecting against rogue DHCP servers.<\/span><\/p>\n<h3><b>Question 258<\/b><\/h3>\n<p><b>Which security concept assumes that every access request should be verified regardless of whether the request originates inside or outside the network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Perimeter trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Zero Trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Implicit trust<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Zero Trust is based on the principle that access should not be automatically trusted because of a user&#8217;s network location. Every access request should be evaluated according to factors such as identity, device security posture, requested resource, context, and applicable policy. Users and devices should receive only the access necessary for legitimate activities. This approach reduces reliance on a traditional network perimeter as the primary security boundary. Open or implicit trust models provide fewer verification requirements. Therefore, Zero Trust is the security concept described in the question.<\/span><\/p>\n<h3><b>Question 259<\/b><\/h3>\n<p><b>Which type of attack uses a compromised legitimate website to deliver malicious content to visitors who belong to a targeted group?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Watering-hole attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Brute-force attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP starvation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password spraying<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A watering-hole attack compromises a legitimate website that is frequently visited by a particular target group. Attackers may use the compromised website to deliver malware, exploit vulnerable browsers, or redirect visitors to malicious resources. The technique can be effective because victims may trust the legitimate website and have no reason to expect malicious content there. Brute-force attacks focus on password guessing, DHCP starvation attempts to exhaust DHCP addresses, and password spraying tries common passwords against multiple accounts. Therefore, a watering-hole attack is the correct answer.<\/span><\/p>\n<h3><b>Question 260<\/b><\/h3>\n<p><b>Which security control provides a separate network segment for public-facing services such as web servers while helping protect the internal network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN trunking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DMZ<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port mirroring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP relay<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A Demilitarized Zone, or DMZ, is a separate network segment commonly used to host systems that need to be accessible from external or less-trusted networks. Public-facing services such as web servers, mail gateways, and certain DNS servers can be placed in the DMZ while internal systems remain behind additional security controls. Firewalls can regulate traffic between the Internet, DMZ, and internal network. VLAN trunking carries multiple VLANs, port mirroring copies traffic for monitoring, and DHCP relay forwards DHCP messages. Therefore, a DMZ provides the described security segmentation.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco 200-201 Exam Dumps and Practice Test Dumps. &nbsp; Question 241 Which security control provides a centralized method for collecting security events from firewalls, servers, and endpoints? NAT DHCP DNS SIEM Correct Answer: 4 Explanation A Security Information and Event Management system, or SIEM, provides centralized collection and analysis of security events from [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14471"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=14471"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14471\/revisions"}],"predecessor-version":[{"id":14490,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14471\/revisions\/14490"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=14471"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=14471"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=14471"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}