350-201 exam dumps

350-201 practice question 155 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 155

Select 3

While investigating a suspected data exfiltration incident, you analyze a packet capture (PCAP) file. You notice multiple TCP streams with unusually large payloads being transmitted to an external IP address. Which of the following artifacts or streams from the PCAP file would you evaluate to confirm whether sensitive data was exfiltrated?

  1. A

    Inspect the payloads of the TCP streams for readable plain-text sensitive data.

  2. B

    Check for encrypted traffic and verify if the encryption protocol is using a known secure standard.

  3. C

    Analyze DNS queries in the packet capture for any suspicious domain names.

  4. D

    Review HTTP POST requests to identify if large amounts of data were sent to external servers.

  5. E

    Examine ARP traffic for unusual address resolutions.

Show answer and explanation

Correct answers: A, C, D

Explanation

To confirm data exfiltration in a packet capture file, you should evaluate streams and artifacts that directly indicate data transfer, such as TCP payloads, suspicious DNS activity, and HTTP POST requests. These artifacts can reveal the presence of sensitive data leaving the network or communication with malicious external entities.

  • A. Correct.

    Inspecting the payloads of the TCP streams is critical to confirm if sensitive data, like plain-text credentials or files, has been transmitted.

  • B. Incorrect.

    Analyzing the encryption protocol is important for ensuring secure communication, but it does not directly confirm data exfiltration unless encryption anomalies are present.

  • C. Correct.

    Suspicious DNS queries, such as queries to uncommon or newly registered domains, can indicate command-and-control communication or data exfiltration.

  • D. Correct.

    HTTP POST requests are commonly used to upload data to servers, making them a key artifact to evaluate for potential exfiltration.

  • E. Incorrect.

    ARP traffic analysis typically focuses on identifying network mapping or spoofing, not data exfiltration.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam