200-201 exam dumps

200-201 practice question 146 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 146

Select 4

A cybersecurity analyst detects unusual behavior on their network where a legitimate service, used for secure communication, is being intercepted and altered by an unauthorized actor. Which of the following actions should the analyst take to confirm and address a potential Man-in-the-Middle (MitM) attack?

  1. A

    Inspect the server's SSL/TLS certificate to verify its authenticity and validity.

  2. B

    Examine the network traffic for suspicious patterns, such as mismatched IP addresses or altered data payloads.

  3. C

    Reboot the affected server to clear any temporary issues with the service.

  4. D

    Review DNS logs for any signs of DNS spoofing or redirection to rogue servers.

  5. E

    Enable port mirroring on the switch to monitor detailed traffic flows.

Show answer and explanation

Correct answers: A, B, D, E

Explanation

Man-in-the-Middle (MitM) attacks involve intercepting and potentially altering communications between two parties. To confirm and mitigate such an attack, it is essential to verify SSL/TLS certificates to ensure authenticity, analyze network traffic for suspicious activity, investigate DNS spoofing attempts, and monitor traffic flows using tools like port mirroring. Rebooting a server does not address the underlying network or security vulnerabilities that allow the attack to occur.

  • A. Correct.

    Inspecting the SSL/TLS certificate can help detect if an attacker is presenting a fraudulent certificate to intercept encrypted traffic.

  • B. Correct.

    Examining network traffic can reveal anomalies indicative of a MitM attack, such as altered data or unexpected IP routing.

  • C. Incorrect.

    Rebooting the server is not an effective method for detecting or mitigating a MitM attack, as it does not address the root cause of the issue.

  • D. Correct.

    Reviewing DNS logs can uncover evidence of DNS spoofing, a common tactic used in MitM attacks to redirect users to malicious servers.

  • E. Correct.

    Enabling port mirroring allows detailed monitoring of traffic, which is crucial for identifying and investigating MitM activities.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam