350-201 exam dumps

350-201 practice question 150 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 150

Select 3

You are investigating a potential data exfiltration incident in your network. To identify the source of the incident, you use a combination of network analysis tools, including a packet capture tool, a traffic analysis tool, and a network log analysis tool. However, you notice that you are unable to fully reconstruct encrypted payloads or correlate certain events. What are the limitations of these tools in such a scenario?

  1. A

    Packet capture tools cannot decrypt encrypted traffic, limiting visibility into the payload.

  2. B

    Traffic analysis tools often lack the ability to provide detailed packet-level information.

  3. C

    Network log analysis tools require accurate time synchronization across devices for effective correlation.

  4. D

    Packet capture tools can automatically detect and block malicious traffic in real-time.

  5. E

    Traffic analysis tools can reconstruct complete encrypted payloads if decryption keys are available.

Show answer and explanation

Correct answers: A, B, C

Explanation

Each tool in the network analysis suite has specific strengths and limitations. Packet capture tools provide granular data but cannot decrypt encrypted traffic. Traffic analysis tools are useful for understanding patterns but lack packet-level detail. Network log analysis tools rely heavily on synchronized timestamps for effective correlation. Understanding these limitations is crucial for selecting the appropriate tool during an investigation.

  • A. Correct.

    Packet capture tools are effective for capturing raw traffic but cannot decrypt encrypted data without access to the appropriate decryption keys, limiting visibility into encrypted payloads.

  • B. Correct.

    Traffic analysis tools are designed to provide high-level insights like patterns or statistics but do not offer packet-level granularity, making them insufficient for certain investigations.

  • C. Correct.

    Network log analysis tools depend on accurate time synchronization (e.g., NTP) to correlate events across devices. Without it, event correlation can be challenging or inaccurate.

  • D. Incorrect.

    Packet capture tools are passive in nature and are not designed to actively block traffic. Their primary role is to collect and analyze data, not to act as a mitigation tool.

  • E. Incorrect.

    Traffic analysis tools cannot reconstruct encrypted payloads, even with decryption keys, as their primary purpose is to analyze traffic patterns, not perform decryption or data reconstruction.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam