200-201 exam dumps

200-201 practice question 89 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 89

Select 4

A security analyst is tasked with identifying a potentially compromised host within a network. The analyst has access to a set of grouped logs containing information about various network connections. Using the 5-tuple approach, which combination of attributes should the analyst focus on to isolate the suspicious activity?

  1. A

    Source IP address

  2. B

    Destination IP address

  3. C

    Protocol used (e.g., TCP, UDP)

  4. D

    Source MAC address

  5. E

    Destination port number

Show answer and explanation

Correct answers: A, B, C, E

Explanation

The 5-tuple approach is a method used to isolate and track network communications. It consists of the source IP address, destination IP address, protocol, source port, and destination port. These attributes collectively help isolate suspicious network flows because they provide detailed information about the origin, destination, communication protocol, and targeted service of the traffic. In this scenario, the source MAC address is not relevant to the 5-tuple approach, as it pertains to the data-link layer rather than the network layer.

  • A. Correct.

    The source IP address, as part of the 5-tuple, helps identify the origin of the traffic and may reveal the compromised host.

  • B. Correct.

    The destination IP address, as part of the 5-tuple, helps identify where the traffic is being sent, which is critical in tracing malicious connections.

  • C. Correct.

    The protocol used (e.g., TCP, UDP) is part of the 5-tuple and helps determine the type of communication being used, which can provide insight into suspicious activity.

  • D. Incorrect.

    The source MAC address is not part of the 5-tuple. The 5-tuple focuses on IP-layer attributes, while the MAC address is part of the data-link layer.

  • E. Correct.

    The destination port number is part of the 5-tuple and is critical for identifying the intended service or application being targeted, which can help pinpoint malicious activity.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam