200-201 exam dumps

200-201 practice question 266 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 266

Select 3

A security analyst is investigating unusual activity on the company network. They notice a high number of outbound requests originating from an internal IP address that does not belong to any assigned device within the organization. Upon further inspection, they suspect this could be an instance of IP spoofing. What action should the analyst take to validate this suspicion and identify potential threats related to the source address?

  1. A

    Verify the MAC address associated with the suspicious IP address in the ARP table.

  2. B

    Use reverse DNS lookup to identify the hostname associated with the suspicious IP address.

  3. C

    Analyze logs for inconsistencies in the source IP address across different time intervals.

  4. D

    Block the suspicious IP address on the firewall immediately to stop all traffic.

  5. E

    Compare the suspicious IP address against threat intelligence feeds for known malicious activity.

Show answer and explanation

Correct answers: A, C, E

Explanation

To validate the suspicion of IP spoofing and identify potential threats, the analyst should use technical methods like verifying the MAC address in the ARP table, analyzing logs for inconsistencies, and consulting threat intelligence feeds. These actions can provide strong indicators of whether the source IP is legitimate or spoofed. Blocking the IP address without investigation or relying solely on reverse DNS lookup would not be effective or appropriate in this scenario.

  • A. Correct.

    Verifying the MAC address in the ARP table can help determine whether the IP address is associated with a legitimate device on the network or if it has been spoofed.

  • B. Incorrect.

    Reverse DNS lookup may provide information about the hostname, but it is not a reliable method for validating IP spoofing as it does not confirm legitimacy.

  • C. Correct.

    Analyzing log data for inconsistencies can help identify abnormalities and determine if the source IP is spoofed or behaving unusually.

  • D. Incorrect.

    Blocking the IP address immediately may disrupt legitimate traffic if the IP address is not actually malicious. Proper investigation should be conducted before taking this action.

  • E. Correct.

    Comparing the suspicious IP address against threat intelligence feeds can help identify if it has been previously associated with known malicious activity.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam