200-201 exam dumps

200-201 practice question 7 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 7

Select 3

A cybersecurity analyst is investigating a security incident where an employee's device was compromised after visiting a malicious website. To prevent similar incidents in the future, the analyst recommends implementing a layered security approach. Which combination of network, endpoint, and application security systems would best mitigate this type of threat?

  1. A

    Web Application Firewall (WAF) to monitor and filter HTTP/HTTPS traffic to web applications

  2. B

    Endpoint Detection and Response (EDR) to monitor and respond to threats on endpoints

  3. C

    URL filtering to block access to known malicious websites

  4. D

    Antivirus software to scan and remove malware on the endpoint

  5. E

    Intrusion Prevention System (IPS) to detect and block malicious network traffic

Show answer and explanation

Correct answers: B, C, D

Explanation

To prevent endpoint compromise from malicious websites, a layered approach is necessary. URL filtering directly blocks access to harmful websites, endpoint detection and response (EDR) monitors and mitigates suspicious behavior on devices, and antivirus software detects and removes malware. While WAF and IPS are valuable security tools, they are not directly relevant to addressing this specific type of threat.

  • A. Incorrect.

    A Web Application Firewall (WAF) is primarily designed to protect web applications from specific attacks like SQL injection or cross-site scripting (XSS). It does not directly prevent endpoint compromise from visiting malicious websites.

  • B. Correct.

    Endpoint Detection and Response (EDR) is effective in monitoring endpoints for suspicious activity and responding to threats, making it a key element in mitigating endpoint-based attacks.

  • C. Correct.

    URL filtering blocks access to known malicious websites, which directly addresses the root cause of this incident and helps prevent similar attacks.

  • D. Correct.

    Antivirus software is essential for detecting and removing malware that may have been downloaded from a malicious website, thereby reducing the risk of further compromise.

  • E. Incorrect.

    An Intrusion Prevention System (IPS) focuses on analyzing and blocking malicious network traffic. While useful, it does not directly address the issue of endpoint compromise from visiting malicious websites.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam