200-201 exam dumps

200-201 practice question 378 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 378

Select 3

A cybersecurity analyst notices unusual activity on a critical server in the network. Upon investigation, they find that the server is listening on an unexpected port (TCP 4444). Which of the following actions should the analyst take to identify potential threats associated with this listening port?

  1. A

    Check the process associated with the listening port using tools like netstat or lsof

  2. B

    Terminate the process immediately to stop any potential malicious activity

  3. C

    Verify if the port is associated with a legitimate service or application

  4. D

    Analyze historical logs to identify when the port started listening and correlate with any changes

  5. E

    Block all traffic to and from the server until further investigation is completed

Show answer and explanation

Correct answers: A, C, D

Explanation

When investigating unusual listening ports, it is important to first identify what process or application is associated with the port and verify if it is legitimate. Analyzing historical logs can provide additional context and help determine if the activity is suspicious. Actions like terminating processes or blocking traffic should only be taken after a thorough investigation to avoid unnecessary disruptions.

  • A. Correct.

    Checking the process associated with the listening port helps identify which application or service is using the port and whether it is legitimate or malicious.

  • B. Incorrect.

    Terminating the process immediately without proper investigation could disrupt legitimate services and may not be the best course of action until the root cause is identified.

  • C. Correct.

    Verifying whether the port is associated with a legitimate service or application is crucial to determine if the activity is expected or potentially malicious.

  • D. Correct.

    Analyzing historical logs provides context about when the port started listening and may help correlate the activity with other events, such as software installation or configuration changes.

  • E. Incorrect.

    Blocking all traffic to and from the server is a drastic action that could negatively affect business operations. It should only be considered as a last resort.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam