exam questions

Exam 350-201 All Questions

View all questions & answers for the 350-201 exam

Exam 350-201 topic 1 question 15 discussion

Actual exam question from Cisco's 350-201
Question #: 15
Topic #: 1
[All 350-201 Questions]

An engineer is analyzing a possible compromise that happened a week ago when the company database servers unexpectedly went down. The analysis reveals that attackers tampered with Microsoft SQL Server Resolution Protocol and launched a DDoS attack. The engineer must act quickly to ensure that all systems are protected. Which two tools should be used to detect and mitigate this type of future attack? (Choose two.)

  • A. firewall
  • B. Wireshark
  • C. autopsy
  • D. SHA512
  • E. IPS
Show Suggested Answer Hide Answer
Suggested Answer: AE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
CiscoTester
Highly Voted 2 years, 4 months ago
Wireshark can't detect or protect, Its: AE
upvoted 8 times
...
archbbo
Most Recent 1 month, 1 week ago
Selected Answer: AE
Wireshark CAN detect but the problem is it happened a week ago, its a live PCAPture, so it wouldnt do no good a week later, the IPS is a fix for future security, and firewall logs can show the evens in the past, so i would go with A and E,
upvoted 1 times
...
ShammaA
10 months, 1 week ago
Selected Answer: AE
Come on now Wireshark? Ofcourse NOT it's IPS & FW
upvoted 2 times
...
ak_technonet
11 months, 2 weeks ago
Selected Answer: AE
Its A & E, Wireshark is not related.
upvoted 2 times
...
jay_c_an
1 year, 1 month ago
took the test today but failed. This is test question.
upvoted 1 times
...
DrVoIP
1 year, 2 months ago
A. Firewall: A firewall is a network security system that monitors and controls incoming and outgoing network traffic based on predetermined security rules. By using a firewall, an organization can block traffic associated with the Microsoft SQL Server Resolution Protocol and DDoS attacks. E. IPS: Intrusion Prevention System (IPS) is a security tool that monitors network traffic for signs of malicious activity and can block or prevent that traffic from entering the network. An IPS can detect and prevent DDoS attacks by identifying suspicious traffic patterns and blocking them. While Wireshark (Option B) and Autopsy (Option C) are both useful network analysis tools, they are not specifically designed for detecting and mitigating DDoS attacks. SHA512 (Option D) is a cryptographic hash function that can be used to verify the integrity of data, but it is not a tool for detecting or mitigating DDoS attacks.
upvoted 1 times
...
Medjai89
1 year, 4 months ago
Wirehsark can also detect but it takes time to understand the packet streams. https://contenthub.netacad.com/courses/cyberops/_common/17.2.6-lab---attacking-a-mysql-database.pdf The question is that it needs to be quik, so answer is definitaly A &E
upvoted 2 times
...
masterchief8047
1 year, 4 months ago
AE is correct.
upvoted 1 times
...
kyle942
1 year, 7 months ago
AB is correct, the server was compromised, https://myakamai.force.com/customers/s/article/Attackers-Using-New-MS-SQL-Reflection-Techniques?language=en_US it was used to launch the attack
upvoted 1 times
TOLU1985
1 year, 7 months ago
so why you say AB? how Wireshark is related?
upvoted 1 times
...
...
kyle942
1 year, 7 months ago
Firewalls and intrusion detection systems that act as traffic-scanning barriers between networks.
upvoted 1 times
...
greeklover84
2 years, 4 months ago
agree A,E
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago