{"id":14479,"date":"2026-09-17T05:07:49","date_gmt":"2026-09-17T05:07:49","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=14479"},"modified":"2026-09-17T05:07:49","modified_gmt":"2026-09-17T05:07:49","slug":"cisco-200-201-practice-test-questions-and-exam-dumps-part20-q381-400","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-200-201-practice-test-questions-and-exam-dumps-part20-q381-400\/","title":{"rendered":"Cisco 200-201 Practice Test Questions and Exam Dumps Part20 Q381-400"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"http:\/\/examlabs.com\/200-201-exam-dumps\"><b>Cisco 200-201 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 381<\/b><\/h3>\n<p><b>Which protocol is commonly used to securely transfer files and commands between network devices through an encrypted SSH connection?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TFTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HTTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Secure Copy Protocol (SCP) provides encrypted file-transfer capabilities through SSH. It allows administrators to securely copy files between systems while protecting authentication credentials and transferred information from network interception. SCP is commonly useful for transferring configuration files, software images, logs, and other administrative data between network devices and servers. FTP and TFTP do not provide the same level of built-in encryption, while HTTP is primarily designed for web communication. Because SCP operates through SSH, it benefits from SSH encryption and authentication mechanisms. Therefore, SCP is the correct protocol for secure file transfers using an SSH connection.<\/span><\/p>\n<h3><b>Question 382<\/b><\/h3>\n<p><b>Which access-control model assigns permissions based primarily on a user&#8217;s organizational role?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RBAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ABAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MAC<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Role-Based Access Control (RBAC) assigns permissions according to predefined roles within an organization. Instead of individually assigning every permission to each user, administrators create roles such as network administrator, help-desk technician, or standard employee and associate appropriate permissions with each role. Users are then assigned to the roles required for their responsibilities. This simplifies administration and helps maintain consistent access policies. DAC allows resource owners to control access, ABAC evaluates multiple attributes, and MAC relies on centrally enforced classifications. Therefore, RBAC is the access-control model that primarily assigns permissions according to organizational roles.<\/span><\/p>\n<h3><b>Question 383<\/b><\/h3>\n<p><b>Which security technology protects DNS information by allowing recipients to validate the authenticity and integrity of DNS responses?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNSSEC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP snooping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPsec<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">DNS Security Extensions (DNSSEC) add cryptographic authentication and integrity protection to DNS data. DNSSEC uses digital signatures so that a resolver can validate whether DNS information originated from an authoritative source and has not been modified. This helps defend against certain DNS spoofing and cache-poisoning attacks. DHCP snooping protects against rogue DHCP servers, IPsec secures IP communications, and RADIUS provides centralized authentication and accounting. DNSSEC does not encrypt ordinary DNS queries and responses; its primary purpose is to provide authenticity and integrity for DNS data. Therefore, DNSSEC is the correct answer.<\/span><\/p>\n<h3><b>Question 384<\/b><\/h3>\n<p><b>Which technology can automatically detect and respond to suspicious activity occurring on an endpoint?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EDR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Endpoint Detection and Response (EDR) continuously monitors endpoint activity and collects security telemetry related to processes, files, network connections, and other system behavior. EDR platforms can detect suspicious activity and provide response capabilities such as terminating malicious processes, collecting forensic information, or isolating a compromised endpoint. NAT translates network addresses, NTP synchronizes system clocks, and DHCP provides IP configuration. EDR is therefore specifically designed to provide visibility and response capabilities at the endpoint level. It is an important component of modern endpoint security and incident-response operations.<\/span><\/p>\n<h3><b>Question 385<\/b><\/h3>\n<p><b>Which security control prevents unauthorized network devices from connecting to a switch port by restricting allowed MAC addresses?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NetFlow<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Port security allows administrators to control which MAC addresses can use a particular switch interface. A switch can be configured with specific secure MAC addresses or can dynamically learn addresses according to a defined policy. If an unauthorized MAC address appears, the switch can apply a configured violation action, such as dropping frames or disabling the interface. DNS filtering controls access to domains, SIEM collects and correlates security events, and NetFlow provides traffic-flow information. Therefore, port security is the appropriate control for restricting which devices can connect through a switch port.<\/span><\/p>\n<h3><b>Question 386<\/b><\/h3>\n<p><b>Which security mechanism can prevent a compromised endpoint from communicating with other systems while it is being investigated?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNSSEC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EDR isolation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SPF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">EDR isolation allows security teams to restrict the network communication of a compromised endpoint while investigation and remediation take place. This can help prevent malware from spreading laterally, contacting command-and-control infrastructure, or accessing additional systems. Depending on the EDR platform, the isolated endpoint may still maintain a limited management connection so security personnel can investigate and respond. DNSSEC protects DNS data, SPF helps authenticate email senders, and NTP synchronizes clocks. Therefore, EDR isolation is the appropriate response mechanism for containing a compromised endpoint during investigation.<\/span><\/p>\n<h3><b>Question 387<\/b><\/h3>\n<p><b>Which attack attempts to deceive users by creating a fraudulent wireless access point with a name similar to a legitimate network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP starvation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Evil twin<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential stuffing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">An evil twin attack involves creating a fraudulent wireless access point that imitates a legitimate network. Attackers may use the same or a very similar SSID to encourage users to connect. Once a victim connects, the attacker may attempt to intercept communications, collect credentials, redirect traffic, or deliver malicious content. SQL injection targets vulnerable database queries, DHCP starvation exhausts available IP addresses, and credential stuffing uses previously stolen credentials against other services. Users should verify trusted wireless networks and avoid entering sensitive information through suspicious connections. Therefore, the attack described is an evil twin attack.<\/span><\/p>\n<h3><b>Question 388<\/b><\/h3>\n<p><b>Which protocol provides secure remote administration by encrypting the communication between an administrator and a network device?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Telnet<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SSH<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TFTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Secure Shell (SSH) provides encrypted remote administration for network devices, servers, and other systems. It protects credentials and interactive command-line sessions from network interception when properly configured. SSH is widely preferred over Telnet because Telnet does not encrypt session information. FTP and TFTP are file-transfer protocols and are not intended to provide secure interactive device administration. SSH can also support secure file-transfer mechanisms such as SCP and SFTP. Therefore, SSH is the correct protocol for securely managing network devices remotely.<\/span><\/p>\n<h3><b>Question 389<\/b><\/h3>\n<p><b>Which security control allows a network device to identify and block traffic from an unauthorized source IP address associated with a switch port?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP Source Guard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Root Guard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BPDU Guard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNSSEC<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">IP Source Guard helps prevent IP address spoofing by restricting traffic based on trusted IP-to-MAC bindings associated with a switch interface. These bindings can be learned through DHCP snooping. If a device attempts to transmit traffic using an IP address that is not authorized for that port, the switch can block the traffic. Root Guard protects the Spanning Tree root role, BPDU Guard protects edge ports from unexpected BPDUs, and DNSSEC protects DNS data. Therefore, IP Source Guard is the security control designed to restrict unauthorized source IP addresses on switch ports.<\/span><\/p>\n<h3><b>Question 390<\/b><\/h3>\n<p><b>Which attack attempts to gain unauthorized access by trying many different passwords against a single account?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password spraying<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential stuffing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Brute-force attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Watering-hole attack<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A brute-force attack attempts to discover a password by repeatedly trying different password combinations against an account or authentication service. Attackers may use automated tools to test large numbers of possible passwords. Password spraying differs because it typically tries a small number of commonly used passwords against many accounts. Credential stuffing uses previously compromised username-and-password combinations, while a watering-hole attack compromises websites visited by a target group. Security controls such as account lockout, multifactor authentication, rate limiting, and strong password policies can reduce brute-force risk. Therefore, the described attack is a brute-force attack.<\/span><\/p>\n<h3><b>Question 391<\/b><\/h3>\n<p><b>Which security principle ensures that information remains protected from unauthorized disclosure?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Availability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Integrity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Confidentiality<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authorization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Confidentiality is the security principle concerned with preventing unauthorized disclosure of information. Organizations can use encryption, access controls, authentication, data classification, and other mechanisms to protect confidential information. Integrity focuses on ensuring that information has not been improperly modified, while availability ensures that authorized users can access resources when needed. Authorization determines what actions an authenticated user is permitted to perform. Confidentiality is particularly important for credentials, financial records, personal information, intellectual property, and other sensitive data. Therefore, confidentiality is the correct security principle.<\/span><\/p>\n<h3><b>Question 392<\/b><\/h3>\n<p><b>Which technology can collect traffic-flow information to help security analysts identify unusual communication patterns?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NetFlow<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">NetFlow provides information about network traffic flows, including source and destination addresses, ports, protocols, packet counts, and byte counts. Security teams can analyze this information to identify unusual traffic patterns, unexpected communications, possible command-and-control activity, or abnormal data transfers. NetFlow generally provides metadata about flows rather than the complete content of every packet. RADIUS provides authentication and accounting services, DHCP provides network configuration, and SCP provides secure file transfer. Therefore, NetFlow is the technology designed to provide network-flow visibility for security and operational analysis.<\/span><\/p>\n<h3><b>Question 393<\/b><\/h3>\n<p><b>Which email-security technology allows a domain owner to specify how receiving systems should handle messages that fail authentication checks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SPF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DKIM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DMARC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SMTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Domain-based Message Authentication, Reporting, and Conformance (DMARC) allows a domain owner to publish policies describing how receiving mail systems should handle messages that fail relevant authentication checks. DMARC works alongside SPF and DKIM and can provide reporting information about authentication results. Organizations can use DMARC policies to instruct receiving systems to monitor, quarantine, or reject certain messages depending on the configured policy. SPF identifies authorized sending servers, DKIM uses cryptographic signatures, and SMTP transports email between mail systems. Therefore, DMARC is the correct technology.<\/span><\/p>\n<h3><b>Question 394<\/b><\/h3>\n<p><b>Which security technology provides centralized collection, correlation, and analysis of logs from multiple network and security devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TFTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Security Information and Event Management (SIEM) systems collect logs and security events from many sources and correlate them to identify potentially suspicious activity. Data can come from firewalls, servers, endpoints, authentication systems, applications, and network devices. Correlation allows security analysts to identify relationships between events and investigate incidents more efficiently. SIEM platforms can also provide alerts, dashboards, reporting, and historical analysis. NTP synchronizes time, TFTP provides basic file transfer, and NAT translates network addresses. Therefore, SIEM is the technology designed for centralized security-event collection and correlation.<\/span><\/p>\n<h3><b>Question 395<\/b><\/h3>\n<p><b>Which security assessment identifies weaknesses in systems without necessarily attempting to exploit them?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Penetration testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incident response<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disaster recovery testing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Vulnerability scanning uses automated tools to identify known or suspected weaknesses in systems, applications, devices, and network services. The scanner may compare system configurations and software versions against vulnerability databases and security rules. Unlike penetration testing, vulnerability scanning generally focuses on identifying potential weaknesses rather than actively attempting to exploit them. Penetration testing involves authorized exploitation to determine whether vulnerabilities can actually be used. Incident response handles security incidents, while disaster recovery testing evaluates restoration procedures. Therefore, vulnerability scanning is the appropriate assessment for identifying weaknesses without necessarily exploiting them.<\/span><\/p>\n<h3><b>Question 396<\/b><\/h3>\n<p><b>Which security technology uses a public and private key pair to support secure communication and authentication?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Symmetric encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hashing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asymmetric cryptography<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Asymmetric cryptography uses a mathematically related public and private key pair. The public key can be distributed openly, while the private key must be protected by its owner. Asymmetric cryptography is used in technologies such as digital certificates, TLS, digital signatures, and secure key exchange. Symmetric encryption uses a shared secret key, hashing produces a one-way digest, and tokenization replaces sensitive information with substitute values. Because asymmetric cryptography relies on separate public and private keys, it is the correct technology described in the question.<\/span><\/p>\n<h3><b>Question 397<\/b><\/h3>\n<p><b>Which security control helps ensure that an organization can recover data after accidental deletion or a destructive cyberattack?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Address Translation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Backups provide copies of data that can be used to restore information after accidental deletion, hardware failure, malware infection, ransomware, or other destructive events. Effective backup strategies should consider backup frequency, retention, storage security, access controls, and restoration testing. Organizations may maintain multiple backup copies, including isolated or offline copies, to reduce the risk that attackers can modify or delete all available backups. Port security controls switch interfaces, DNS filtering controls access to domains, and NAT translates network addresses. Therefore, backups are the appropriate recovery control for protecting against data loss.<\/span><\/p>\n<h3><b>Question 398<\/b><\/h3>\n<p><b>Which security mechanism can detect unauthorized modifications to critical files by comparing their current hashes with trusted baseline hashes?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File integrity monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP snooping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">File Integrity Monitoring (FIM) can detect unauthorized changes by comparing current file characteristics with a trusted baseline. Cryptographic hashes are commonly used because a change to the file contents generally results in a different hash value. FIM can monitor operating-system files, configuration files, application components, and other sensitive resources. SIEM systems collect and correlate events, RADIUS provides centralized authentication and accounting, and DHCP snooping protects against unauthorized DHCP servers. Therefore, file integrity monitoring is the mechanism that can identify unauthorized file modifications through hash comparison.<\/span><\/p>\n<h3><b>Question 399<\/b><\/h3>\n<p><b>Which security architecture assumes that users and devices should not automatically be trusted based only on their network location?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Zero Trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat network<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Perimeter-only security<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Zero Trust is based on the principle that users and devices should not receive automatic trust simply because they are located inside an organization&#8217;s network. Access decisions can consider identity, device posture, resource sensitivity, authentication status, and other contextual information. Access is limited according to policy and can be continuously evaluated. This approach can reduce the potential impact of compromised accounts and endpoints by limiting unnecessary access. A flat network and perimeter-only security rely more heavily on network location and traditional boundaries. Therefore, Zero Trust is the appropriate security architecture.<\/span><\/p>\n<h3><b>Question 400<\/b><\/h3>\n<p><b>Which security control provides a separate network segment for public-facing services while helping protect the internal network from direct exposure?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN trunking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP relay<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DMZ<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Loopback interface<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A Demilitarized Zone (DMZ) provides a separate network segment for services that need to be accessible from external networks. Public-facing systems such as web, mail, and DNS servers can be placed in the DMZ while firewalls control communication between the Internet, DMZ, and internal network. This architecture creates an additional security boundary and can limit the impact of a compromise involving an externally accessible server. VLAN trunking carries multiple VLANs, DHCP relay forwards DHCP messages, and a loopback interface is a logical interface. Therefore, the DMZ is the correct security architecture.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco 200-201 Exam Dumps and Practice Test Dumps. &nbsp; Question 381 Which protocol is commonly used to securely transfer files and commands between network devices through an encrypted SSH connection? FTP TFTP HTTP SCP Correct Answer: 4 Explanation Secure Copy Protocol (SCP) provides encrypted file-transfer capabilities through SSH. It allows administrators to securely [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14479"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=14479"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14479\/revisions"}],"predecessor-version":[{"id":14483,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14479\/revisions\/14483"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=14479"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=14479"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=14479"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}