200-201 exam dumps

200-201 practice question 157 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 157

Select 3

An attacker is attempting to exfiltrate sensitive data from a corporate network without being detected by security monitoring tools. The attacker disguises the malicious traffic within legitimate HTTPS traffic and routes it through an intermediary server to hide their origin. Which evasion and obfuscation techniques are being used in this scenario?

  1. A

    Tunneling

  2. B

    Encryption

  3. C

    Proxies

  4. D

    Code Injection

  5. E

    Credential Harvesting

Show answer and explanation

Correct answers: A, B, C

Explanation

The attacker in the scenario uses a combination of tunneling, encryption, and proxies to evade detection. By encapsulating malicious traffic within HTTPS (tunneling), encrypting the data (encryption), and routing it through an intermediary server (proxies), the attacker successfully disguises their activities. These techniques are common methods used to bypass network security tools such as intrusion detection systems.

  • A. Correct.

    Tunneling is the process of encapsulating malicious traffic within legitimate network protocols, such as HTTPS, to evade detection. In this scenario, the attacker is using tunneling to blend malicious traffic with normal HTTPS traffic.

  • B. Correct.

    Encryption is used to secure the contents of communication, making it difficult for monitoring tools to inspect the traffic. Here, HTTPS encryption is being utilized to obfuscate the data being exfiltrated.

  • C. Correct.

    Proxies act as intermediaries to route traffic and hide the true source of communication. The attacker is using an intermediary server (a proxy) to disguise their origin.

  • D. Incorrect.

    Code injection involves inserting malicious code into a legitimate application or process. While a common attack technique, it is not relevant in this scenario where the focus is on traffic evasion and obfuscation.

  • E. Incorrect.

    Credential harvesting refers to stealing user credentials, such as usernames and passwords. This is unrelated to the described scenario, which focuses on traffic obfuscation techniques.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam