200-201 exam dumps

200-201 practice question 209 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 209

Select 3

A cybersecurity analyst is investigating a suspected phishing attack on their organization. While analyzing network traffic logs, the analyst finds unusual outbound traffic patterns from an internal workstation to an unknown IP address. There are no direct log entries or explicit evidence of malicious activity on the workstation. Which of the following observations could be considered indirect evidence supporting the analysis?

  1. A

    The workstation accessed domains that were recently registered and have no reputation history.

  2. B

    A malware detection alert was triggered by the antivirus software on the workstation.

  3. C

    The outbound traffic from the workstation matches the behavior of known command-and-control beaconing patterns.

  4. D

    The user of the workstation reported receiving a suspicious email prior to the traffic being observed.

  5. E

    The unknown IP address has been flagged on a threat intelligence platform as malicious.

Show answer and explanation

Correct answers: A, C, D

Explanation

Indirect evidence refers to observations or data points that imply malicious activity but do not explicitly confirm it. In this scenario, unusual access to recently registered domains, traffic matching command-and-control patterns, and a user-reported suspicious email are all contextual clues that suggest potential compromise. However, direct evidence, such as malware detection or a flagged malicious IP, provides explicit confirmation of an issue.

  • A. Correct.

    Recently registered domains with no reputation history suggest potential malicious activity, but this is not direct evidence. It is an example of indirect evidence.

  • B. Incorrect.

    A malware detection alert is direct evidence of malicious activity, not indirect evidence.

  • C. Correct.

    The outbound traffic resembling known command-and-control patterns is indirect evidence as it implies malicious activity without providing definitive proof.

  • D. Correct.

    A user-reported suspicious email is indirect evidence as it contextualizes the timing of the unusual activity but does not directly prove malicious intent.

  • E. Incorrect.

    A flagged IP address on a threat intelligence platform is direct evidence, as it explicitly identifies a known malicious entity.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam