Go Back on 200-201 Exam
Available in 1, 3, 6 and 12 Months Free Updates Plans
PDF: $15 $60

Test Engine: $20 $80

PDF + Engine: $25 $99

200-201 Practice Test


Page 2 out of 37 Pages

Which two elements of the incident response process are stated in NIST Special
Publication 800-61 r2? (Choose two.)


A.

detection and analysis


B.

post-incident activity


C.

vulnerability management


D.

risk assessment





A.
  

detection and analysis



B.
  

post-incident activity



Reference: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

A security engineer has a video of a suspect entering a data center that was captured on  the same day that files in the same data center were transferred to a competitor. Which type of evidence is this?


A.

best evidence


B.

prima facie evidence


C.

indirect evidence


D.

physical evidence





C.
  

indirect evidence



the same day that files in the same data center were transferred to a competitor.
Which type of evidence is this?


A.

best evidence


B.

prima facie evidence


C.

indirect evidence


D.

physical evidence





C.
  

indirect evidence



A security engineer has a video of a suspect entering a data center that was captured on the same day that files in the same data center were transferred to a competitor. Which type of evidence is this?


A.

best evidence


B.

prima facie evidence


C.

indirect evidence


D.

Dphysical evidence





C.
  

indirect evidence



Refer to the exhibit.


Which two elements in the table are parts of the 5-tuple? (Choose two.)


A.

A. First Packet


B.

 Initiator User


C.

Ingress Security Zone


D.

Source Port


E.

Initiator IP





D.
  

Source Port



E.
  

Initiator IP




Page 2 out of 37 Pages
Previous