{"id":14472,"date":"2026-09-17T05:08:46","date_gmt":"2026-09-17T05:08:46","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=14472"},"modified":"2026-09-17T05:08:46","modified_gmt":"2026-09-17T05:08:46","slug":"cisco-200-201-practice-test-questions-and-exam-dumps-part14-q261-280","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-200-201-practice-test-questions-and-exam-dumps-part14-q261-280\/","title":{"rendered":"Cisco 200-201 Practice Test Questions and Exam Dumps Part14 Q261-280"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"http:\/\/examlabs.com\/200-201-exam-dumps\"><b>Cisco 200-201 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 261<\/b><\/h3>\n<p><b>Which authentication protocol is commonly used with 802.1X to transport authentication messages between a supplicant and an authentication server?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EAP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TFTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Extensible Authentication Protocol (EAP) provides a framework for carrying authentication information between network access components. In an 802.1X environment, a supplicant communicates with an authenticator, while authentication information is ultimately processed by an authentication server such as a RADIUS server. EAP supports different authentication methods, including certificate-based and credential-based mechanisms. FTP and TFTP are file-transfer protocols, while SNMP is primarily used for network management and monitoring. EAP is therefore the appropriate technology for carrying flexible authentication methods within an 802.1X network-access environment.<\/span><\/p>\n<h3><b>Question 262<\/b><\/h3>\n<p><b>Which Cisco security feature can dynamically learn endpoint information and use it to create a binding between an IP address and MAC address?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Root Guard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP snooping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BPDU Guard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNSSEC<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">DHCP snooping can create a binding database containing information such as IP addresses, MAC addresses, VLANs, and switch interfaces learned from legitimate DHCP transactions. This database can then support other security features, including Dynamic ARP Inspection and IP Source Guard. DHCP snooping also helps prevent unauthorized DHCP servers by identifying trusted and untrusted interfaces. Root Guard and BPDU Guard protect Spanning Tree Protocol operations, while DNSSEC protects DNS responses. Therefore, DHCP snooping is the feature that dynamically learns IP-to-MAC binding information from DHCP activity.<\/span><\/p>\n<h3><b>Question 263<\/b><\/h3>\n<p><b>Which Spanning Tree security feature protects a switch port from receiving unexpected BPDUs by placing the port into an error-disabled state?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Root Guard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Loop Guard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BPDU Guard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">PortFast<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">BPDU Guard is designed to protect edge ports, especially ports connected to end-user devices, from unexpected Bridge Protocol Data Units. When BPDU Guard is enabled and a BPDU is received on a protected port, the switch can place the port into an error-disabled state. This helps prevent unauthorized switches from influencing the Spanning Tree topology. Root Guard provides protection against unauthorized root-bridge changes, while Loop Guard helps prevent certain unidirectional-link problems. PortFast accelerates transition to the forwarding state but does not itself provide BPDU protection. Therefore, BPDU Guard is correct.<\/span><\/p>\n<h3><b>Question 264<\/b><\/h3>\n<p><b>Which attack attempts to overwhelm a switch&#8217;s CAM table with many fake MAC addresses?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN hopping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP starvation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP spoofing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MAC flooding<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A MAC flooding attack attempts to fill a switch&#8217;s Content Addressable Memory (CAM) table with large numbers of false MAC addresses. When the table becomes exhausted, the switch may have difficulty determining the correct destination port for frames and can flood traffic within the relevant VLAN. This behavior can potentially allow an attacker to observe traffic that would normally be forwarded only to a specific port. VLAN hopping targets VLAN boundaries, DHCP starvation exhausts DHCP address pools, and ARP spoofing manipulates ARP information. Therefore, MAC flooding is the correct attack.<\/span><\/p>\n<h3><b>Question 265<\/b><\/h3>\n<p><b>Which access-control method assigns permissions according to predefined job roles?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RBAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ABAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MAC<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Role-Based Access Control (RBAC) assigns permissions based on organizational roles rather than individually assigning every permission to every user. For example, employees in a network-administrator role may receive administrative permissions, while help-desk personnel receive a more limited set of privileges. This approach simplifies access management when many users have similar responsibilities. Discretionary Access Control allows resource owners to control permissions, while Attribute-Based Access Control evaluates attributes and policies. Mandatory Access Control uses centrally defined security classifications and rules. Therefore, RBAC is the appropriate access-control model for job-based permissions.<\/span><\/p>\n<h3><b>Question 266<\/b><\/h3>\n<p><b>Which security technology verifies that DNS responses have not been modified by using cryptographic signatures?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SPF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNSSEC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP snooping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">DNS Security Extensions (DNSSEC) use digital signatures to provide authenticity and integrity for DNS data. DNSSEC helps clients verify that DNS responses originate from the expected authoritative source and have not been altered during transmission. This can help defend against certain DNS spoofing and cache-poisoning attacks. SPF serves a different purpose by publishing information about authorized mail-sending servers. DHCP snooping protects against unauthorized DHCP activity, while RADIUS supports centralized authentication and authorization. Therefore, DNSSEC is the technology that uses cryptographic signatures to validate DNS information.<\/span><\/p>\n<h3><b>Question 267<\/b><\/h3>\n<p><b>Which VPN type is designed primarily for an individual user connecting securely to an organization&#8217;s network from a remote location?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Site-to-site VPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remote-access VPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DMZ<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A remote-access VPN allows an individual user to establish a secure connection to an organization&#8217;s network from an external location. The user typically runs a VPN client or uses a supported secure access mechanism to authenticate and establish an encrypted tunnel. This is useful for employees working from home, traveling, or accessing organizational resources from other locations. A site-to-site VPN is generally designed to connect entire networks rather than individual users. A DMZ provides network segmentation, while NAT translates IP addresses. Therefore, remote-access VPN is correct.<\/span><\/p>\n<h3><b>Question 268<\/b><\/h3>\n<p><b>Which cryptographic method uses the same secret key for both encryption and decryption?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asymmetric encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Digital signature<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Symmetric encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hashing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Symmetric encryption uses the same secret key, or a closely related shared secret, to encrypt and decrypt information. Because the same secret must be available to authorized parties, protecting and distributing the key securely is an important consideration. Symmetric algorithms are commonly used when efficient encryption of large amounts of data is required. Asymmetric cryptography uses a public and private key pair, digital signatures provide authentication and integrity functions, and hashing creates a one-way digest rather than reversible encryption. Therefore, symmetric encryption is the cryptographic method described.<\/span><\/p>\n<h3><b>Question 269<\/b><\/h3>\n<p><b>Which security device is specifically designed to inspect HTTP and HTTPS requests and help protect web applications from attacks such as SQL injection?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">WAF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Wireless controller<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A Web Application Firewall (WAF) is designed to protect web applications by inspecting HTTP and HTTPS traffic. It can identify and block malicious requests associated with attacks such as SQL injection, cross-site scripting, and certain application-layer exploits. A WAF operates with awareness of web traffic and application protocols, making it different from a traditional network firewall that primarily controls network connections according to addresses, ports, and protocols. DHCP servers provide network configuration, NTP servers synchronize clocks, and wireless controllers manage wireless infrastructure. Therefore, WAF is correct.<\/span><\/p>\n<h3><b>Question 270<\/b><\/h3>\n<p><b>Which security control can prevent an endpoint from communicating with the network after EDR detects that the endpoint has been compromised?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File hashing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Endpoint isolation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Endpoint isolation is a response capability that can restrict a compromised endpoint&#8217;s network communication while allowing security administrators to investigate and manage the device. EDR platforms commonly provide isolation capabilities as part of their incident-response features. Isolating an infected endpoint can help limit lateral movement and reduce the opportunity for malware to spread to other systems. File hashing helps identify file changes, network segmentation separates network zones, and data compression reduces data size. Therefore, endpoint isolation is the most appropriate control for rapidly containing a compromised endpoint.<\/span><\/p>\n<h3><b>Question 271<\/b><\/h3>\n<p><b>Which authentication method uses a physical smart card or security token as part of verifying a user&#8217;s identity?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Something you know<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Something you are<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Something you have<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Somewhere you are<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Authentication factors are commonly categorized into knowledge, possession, and inherence factors. Something you have refers to a physical item possessed by the user, such as a smart card, hardware security token, or certain authentication devices. Something you know refers to information such as a password or PIN. Something you are refers to a biometric characteristic such as a fingerprint. Using multiple factor categories can provide stronger authentication than relying on a password alone. Therefore, a physical smart card or security token represents the \u201csomething you have\u201d authentication factor.<\/span><\/p>\n<h3><b>Question 272<\/b><\/h3>\n<p><b>Which security technology can identify and block malicious or inappropriate domains before a user&#8217;s device connects to the destination?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS security filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BPDU Guard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP relay<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">DNS security filtering can evaluate domain-name requests against security intelligence and organizational policies before allowing the connection to proceed. If a requested domain is associated with malware, phishing, command-and-control infrastructure, or another blocked category, the DNS security service can prevent the resolution or redirect the request to a safe response. This provides an additional security layer before a user establishes communication with the destination. Port security controls switch-port access, BPDU Guard protects Spanning Tree edge ports, and DHCP relay forwards DHCP messages. Therefore, DNS security filtering is correct.<\/span><\/p>\n<h3><b>Question 273<\/b><\/h3>\n<p><b>Which type of malware is designed to secretly provide unauthorized privileged access to a system while attempting to hide its presence?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Worm<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rootkit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Adware<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ransomware<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A rootkit is a type of malicious software designed to maintain unauthorized access while hiding its activities from users and security tools. Rootkits may operate at different levels of a system and can modify operating-system components or other mechanisms to conceal processes, files, network connections, or other indicators of compromise. Worms are primarily characterized by their ability to self-propagate, ransomware encrypts or otherwise locks data to extort victims, and adware primarily displays unwanted advertising. Therefore, a rootkit best matches the described behavior.<\/span><\/p>\n<h3><b>Question 274<\/b><\/h3>\n<p><b>Which email-security technology allows a domain owner to publish a policy describing how receiving mail systems should handle messages that fail SPF or DKIM checks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SMTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IMAP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DMARC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">POP3<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Domain-based Message Authentication, Reporting, and Conformance (DMARC) allows a domain owner to publish instructions for handling email messages that fail authentication checks involving SPF and\/or DKIM. DMARC can also provide reporting information that helps organizations understand authentication results and potential abuse of their domains. SMTP is responsible for transferring email between mail systems, while IMAP and POP3 are primarily used for retrieving messages. DMARC therefore provides the policy and reporting framework that complements SPF and DKIM and helps organizations address email-domain impersonation.<\/span><\/p>\n<h3><b>Question 275<\/b><\/h3>\n<p><b>Which type of attack involves sending repeated fraudulent ARP messages to associate an attacker&#8217;s MAC address with another host&#8217;s IP address?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP spoofing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS tunneling<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MAC flooding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP starvation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">ARP spoofing occurs when an attacker sends forged Address Resolution Protocol messages to manipulate the relationship between IP addresses and MAC addresses. The attacker may attempt to associate their own MAC address with the IP address of another host, such as the default gateway. This can allow traffic to be redirected through the attacker&#8217;s system and potentially support man-in-the-middle activity. MAC flooding targets the switch CAM table, DHCP starvation consumes available DHCP addresses, and DNS tunneling abuses DNS communications. Therefore, ARP spoofing is the correct attack.<\/span><\/p>\n<h3><b>Question 276<\/b><\/h3>\n<p><b>Which security control can restrict a switch port so that only specific MAC addresses are allowed to connect?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNSSEC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPsec<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Switch port security can restrict which MAC addresses are permitted to use a particular switch interface. Administrators can configure specific secure MAC addresses or allow the switch to dynamically learn addresses according to the configured policy. If an unauthorized device connects, the switch can take actions such as dropping frames, generating alerts, or disabling the port, depending on the violation mode. DNSSEC protects DNS integrity, RADIUS provides centralized authentication services, and IPsec secures IP communications. Therefore, port security is the appropriate control for restricting MAC addresses on a switch port.<\/span><\/p>\n<h3><b>Question 277<\/b><\/h3>\n<p><b>Which security assessment actively attempts to exploit identified vulnerabilities to determine whether they can actually be used by an attacker?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset inventory<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Penetration testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log collection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Penetration testing is a security assessment in which authorized testers attempt to exploit vulnerabilities in a controlled environment. The objective is to determine whether weaknesses can actually be used and to understand their potential impact. Vulnerability scanning generally focuses on identifying and reporting suspected weaknesses without necessarily exploiting them. Asset inventory identifies systems and resources, while log collection gathers security and operational events. Penetration testing should be carefully authorized and scoped to prevent unintended disruption. Therefore, penetration testing is the assessment that actively attempts to exploit vulnerabilities.<\/span><\/p>\n<h3><b>Question 278<\/b><\/h3>\n<p><b>Which protocol provides encrypted remote administration of network devices and servers?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Telnet<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SSH<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HTTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Secure Shell (SSH) provides encrypted remote administration for network devices, servers, and other systems. SSH protects credentials and interactive session data from interception when properly configured. It can also provide secure file-transfer capabilities through related technologies such as SCP and SFTP. Telnet provides remote access without encryption, FTP is primarily a file-transfer protocol and is insecure by default, and HTTP is designed for web communication. For secure command-line administration across an untrusted network, SSH is therefore the appropriate protocol.<\/span><\/p>\n<h3><b>Question 279<\/b><\/h3>\n<p><b>Which incident-response phase focuses on removing malware, compromised accounts, and other causes of the security incident?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Preparation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Containment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Eradication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Eradication is the incident-response phase focused on eliminating the root cause and malicious components of an incident. Depending on the situation, this can include removing malware, deleting persistence mechanisms, disabling compromised accounts, applying security patches, and addressing vulnerabilities that enabled the attack. Preparation occurs before incidents and establishes processes and resources. Identification focuses on recognizing and analyzing the incident, while containment limits its spread and impact. Therefore, eradication is the phase responsible for removing the threat and addressing the underlying cause.<\/span><\/p>\n<h3><b>Question 280<\/b><\/h3>\n<p><b>Which backup strategy creates a complete copy of all selected data during each backup operation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incremental backup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Differential backup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Full backup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Snapshot-only backup<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A full backup creates a complete copy of all selected data each time the backup is performed. Because every backup contains the entire selected dataset, restoration can be straightforward because the organization generally needs the full backup itself rather than combining multiple incremental backup sets. The trade-off is that full backups typically require more storage space and can take longer to complete. Incremental backups copy data changed since the previous backup, while differential backups copy data changed since the last full backup. Therefore, a full backup is the correct answer.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco 200-201 Exam Dumps and Practice Test Dumps. &nbsp; Question 261 Which authentication protocol is commonly used with 802.1X to transport authentication messages between a supplicant and an authentication server? EAP FTP SNMP TFTP Correct Answer: 1 Explanation Extensible Authentication Protocol (EAP) provides a framework for carrying authentication information between network access components. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14472"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=14472"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14472\/revisions"}],"predecessor-version":[{"id":14489,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14472\/revisions\/14489"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=14472"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=14472"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=14472"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}