Go Back on 200-201 Exam
Available in 1, 3, 6 and 12 Months Free Updates Plans
PDF: $15 $60

Test Engine: $20 $80

PDF + Engine: $25 $99

200-201 Practice Test


Page 11 out of 37 Pages

An investigator is examining a copy of an ISO file that is stored in CDFS format.
What type of evidence is this file?


A.

data from a CD copied using Mac-based system


B.

data from a CD copied using Linux system


C.

data from a DVD copied using Windows system


D.

data from a CD copied using Windows





B.
  

data from a CD copied using Linux system



Which type of evidence supports a theory or an assumption that results from initial
evidence?


A.

probabilistic


B.

indirect


C.

best


D.

corroborative





D.
  

corroborative



Refer to the exhibit.
What is the expected result when the "Allow subdissector to reassemble TCP streams" feature is enabled?


A.

insert TCP subdissectors


B.

extract a file from a packet capture


C.

disable TCP streams


D.

unfragment TCP





D.
  

unfragment TCP



Refer to the exhibit.
What is occurring in this network traffic?


A.

high rate of SYN packets being sent from a multiple source towards a single destination IP


B.

high rate of SYN packets being sent from a single source IP towards multiple destination IPs


C.

flood of ACK packets coming from a single source IP to multiple destination IPs


D.

flood of SYN packets coming from a single source IP to a single destination IP





D.
  

flood of SYN packets coming from a single source IP to a single destination IP



One of the objectives of information security is to protect the CIA of information and systems. What does CIA mean in this context?


A.

confidentiality, identity, and authorization


B.

confidentiality, integrity, and authorization


C.

confidentiality, identity, and availability


D.

confidentiality, integrity, and availability





D.
  

confidentiality, integrity, and availability




Page 11 out of 37 Pages
Previous