200-201 exam dumps

200-201 practice question 185 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 185

Single answer

A cybersecurity analyst is investigating a suspected malware infection on a workstation. The analyst notices that the host-based firewall on the workstation has been disabled, but there are no administrative records of this action. What is the most likely reason the host-based firewall was disabled?

  1. A

    A legitimate system update required the firewall to be temporarily disabled.

  2. B

    The malware disabled the host-based firewall to allow unrestricted access to the system.

  3. C

    The user manually disabled the firewall to troubleshoot a network issue.

  4. D

    The firewall was disabled by the organization's IT policy for compliance reasons.

Show answer and explanation

Correct answer: B

Explanation

Malware commonly disables host-based firewalls as part of its strategy to compromise system security. Doing so allows the malware to communicate with command-and-control servers or spread laterally without being blocked by the firewall. In this scenario, the absence of administrative records and the suspicious nature of the system activity strongly indicate that malware is the cause of the disabled firewall.

  • A. Incorrect.

    Legitimate system updates do not typically require the firewall to be disabled. Such updates are designed to work without compromising system security.

  • B. Correct.

    Malware often disables host-based firewalls to bypass network restrictions and allow malicious traffic to enter or leave the system without detection. This is the most likely scenario in this case.

  • C. Incorrect.

    While users may sometimes disable firewalls for troubleshooting, this scenario involves no evidence suggesting user intervention or administrative approval.

  • D. Incorrect.

    Disabling firewalls for compliance reasons is highly unusual and counterproductive to security. IT policies typically strengthen security rather than weaken it.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam