350-201 exam dumps

350-201 practice question 216 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 216

Select 3

A security analyst at your organization is investigating unusual network activity and suspects a potential compromise. During the investigation, the analyst identifies repeated connections to an external IP address that is blacklisted, unauthorized file transfers to an unknown server, and abnormal login attempts from multiple geographic locations. Based on this scenario, which of the following are valid Indicators of Compromise (IOCs) or Indicators of Attack (IOAs)?

  1. A

    Repeated connections to a known blacklisted IP address

  2. B

    Abnormal login attempts from multiple geographic locations

  3. C

    A user accessing a company-approved cloud storage service

  4. D

    Unauthorized file transfers to an unknown server

  5. E

    Scheduled system updates occurring outside of regular maintenance windows

Show answer and explanation

Correct answers: A, B, D

Explanation

Indicators of Compromise (IOCs) and Indicators of Attack (IOAs) are critical in identifying and responding to potential security incidents. Repeated connections to blacklisted IPs, abnormal login attempts, and unauthorized file transfers are clear indicators of malicious activity. These provide evidence of compromise or ongoing attacks, requiring immediate investigation and response. Non-suspicious or unrelated activities, such as accessing approved resources, do not qualify as IOCs or IOAs unless further evidence suggests otherwise.

  • A. Correct.

    Repeated connections to a known blacklisted IP address are a strong IOC, as they signify communication with a potentially malicious entity.

  • B. Correct.

    Abnormal login attempts from multiple geographic locations indicate suspicious behavior, making this a valid IOA that may signal account compromise or malicious activity.

  • C. Incorrect.

    Accessing a company-approved cloud storage service alone is not inherently suspicious and does not qualify as an IOC or IOA unless combined with unusual behavior.

  • D. Correct.

    Unauthorized file transfers to an unknown server strongly indicate malicious activity and are a valid IOC.

  • E. Incorrect.

    Scheduled system updates occurring outside of regular maintenance windows could indicate misconfiguration or policy deviation, but alone, they are not definitive IOCs or IOAs without additional context.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam