350-201 exam dumps

350-201 practice question 58 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 58

Select 3

A security analyst is tasked with evaluating the security posture of a mission-critical server within the organization's network. Which of the following steps should the analyst take as part of this process?

  1. A

    Identify and classify the server's data and its level of sensitivity.

  2. B

    Review the server's patch management status and ensure it is updated with the latest security patches.

  3. C

    Perform a penetration test on the server without notifying other teams for real-world simulation.

  4. D

    Analyze access controls to ensure only authorized users can access the server's data and services.

  5. E

    Disable all network monitoring tools temporarily to avoid interference during the evaluation.

Show answer and explanation

Correct answers: A, B, D

Explanation

Evaluating the security posture of an asset involves identifying its criticality and sensitivity, ensuring it is protected against known vulnerabilities, and verifying that access controls are properly configured. These steps help determine the asset's current security standing and areas for improvement. Actions that reduce visibility or deviate from established processes are not appropriate during this evaluation.

  • A. Correct.

    Correct: Identifying and classifying the server's data is essential to understanding its criticality and sensitivity, which directly affects its security requirements.

  • B. Correct.

    Correct: Reviewing patch management ensures the server is protected against known vulnerabilities, which is a key part of evaluating its security posture.

  • C. Incorrect.

    Incorrect: Performing a penetration test without notifying other teams can lead to unintended consequences and is not standard practice during a security posture evaluation.

  • D. Correct.

    Correct: Analyzing access controls is crucial to ensure that only authorized users can access the server, reducing the risk of unauthorized access.

  • E. Incorrect.

    Incorrect: Disabling network monitoring tools would reduce visibility into potential threats and is counterproductive to maintaining security.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam