350-201 exam dumps

350-201 practice question 151 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 151

Select 3

A cybersecurity analyst is troubleshooting a suspected data exfiltration incident within their network. They decide to use various tools to analyze the network traffic and logs. Which of the following tools and their limitations should the analyst consider when investigating the incident?

  1. A

    Packet capture tools, which provide detailed insights into individual packets but can be overwhelming when dealing with large volumes of traffic.

  2. B

    Traffic analysis tools, which summarize traffic patterns but lack granular visibility into specific payload contents.

  3. C

    Network log analysis tools, which provide historical data but may not include real-time traffic insights.

  4. D

    Intrusion prevention systems (IPS), which proactively block malicious traffic but do not provide retrospective analysis for past events.

  5. E

    Antivirus tools, which are effective at detecting malware but are not designed for network-level traffic analysis.

Show answer and explanation

Correct answers: A, B, C

Explanation

The correct answers focus on tools relevant to network analysis and their limitations in the context of investigating suspected data exfiltration. Packet capture tools, traffic analysis tools, and network log analysis tools each provide unique capabilities for identifying suspicious activity but also have specific limitations. Intrusion prevention systems and antivirus tools are not appropriate for the described scenario because they serve different purposes, such as proactive blocking or endpoint protection.

  • A. Correct.

    Packet capture tools, such as Wireshark, are highly effective for detailed analysis but can generate massive amounts of data, making it challenging to isolate relevant information in large-scale incidents.

  • B. Correct.

    Traffic analysis tools, like NetFlow or Cisco Stealthwatch, provide high-level summaries of traffic patterns, which are useful for identifying anomalies but lack the ability to inspect payload-level details.

  • C. Correct.

    Network log analysis tools, such as Splunk or ELK, are excellent for reviewing historical activity but do not provide real-time visibility into live network traffic.

  • D. Incorrect.

    Intrusion prevention systems (IPS) are designed for blocking malicious traffic in real-time, but they are not intended for retrospective analysis of past events, which is the focus of the scenario.

  • E. Incorrect.

    Antivirus tools are endpoint protection solutions and are not applicable for analyzing or troubleshooting network traffic.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam