200-201 exam dumps

200-201 practice question 76 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 76

Select 3

A security analyst in your team is tasked with investigating a suspected data exfiltration incident involving a privileged user account. To properly analyze the system logs and access the required forensic data from the affected server, which privileges are necessary for the analyst to perform their tasks effectively?

  1. A

    Administrator-level privileges to access all logs and system configurations

  2. B

    Read-only access to system logs to prevent accidental changes

  3. C

    Write permissions to modify system files for further investigation

  4. D

    Access to network capture files from firewalls or IDS/IPS systems

  5. E

    User-level access to verify user activity related to the incident

Show answer and explanation

Correct answers: A, B, D

Explanation

Investigating a data exfiltration incident often requires elevated privileges to access system logs, configurations, and network data. Administrator-level privileges ensure comprehensive access, while read-only log access maintains evidence integrity. Additionally, network capture files help trace activity related to the incident. Write permissions and user-level access are either unnecessary or insufficient for this purpose.

  • A. Correct.

    Administrator-level privileges are often required to access sensitive logs and system configurations critical for investigating incidents. Without this privilege, the analyst might be blocked from obtaining all necessary information.

  • B. Correct.

    Read-only access to logs ensures the integrity of the forensic evidence while allowing the security analyst to review the data. Preventing accidental or intentional alterations is essential in an investigation.

  • C. Incorrect.

    Write permissions to modify system files are not necessary and could compromise the evidence, making it inadmissible in legal or compliance scenarios.

  • D. Correct.

    Access to network capture files from firewalls or IDS/IPS systems is important for analyzing traffic patterns and identifying anomalies related to data exfiltration.

  • E. Incorrect.

    User-level access is insufficient for the investigation as it does not provide the required visibility into system or network-level activities.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam