Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 350-201 Exam - Topic 2 Question 117 Discussion

Refer to the exhibit.An engineer is investigating a case with suspicious usernames within the active directory. After the engineer investigates and cross-correlates events from other sources, it appears that the 2 users are privileged, and their creation date matches suspicious network traffic that was initiated from the internal network 2 days prior. Which type of compromise is occurring?
D) compromised network
A) compromised insider
B) compromised root access
C) compromised database tables

Cisco 350-201 Exam - Topic 2 Question 117 Discussion

Actual exam question for Cisco's 350-201 exam
Question #: 117
Topic #: 2
[All 350-201 Questions]

Refer to the exhibit.

An engineer is investigating a case with suspicious usernames within the active directory. After the engineer investigates and cross-correlates events from other sources, it appears that the 2 users are privileged, and their creation date matches suspicious network traffic that was initiated from the internal network 2 days prior. Which type of compromise is occurring?

Show Suggested Answer Hide Answer
Suggested Answer: D

Contribute your Thoughts:

0/2000 characters
Herminia
5 months ago
I lean towards D) compromised network. The traffic is a big clue.
upvoted 0 times
...
Thomasena
5 months ago
True, but the focus is on the usernames. Insider makes more sense.
upvoted 0 times
...
Dianne
5 months ago
But what about B) compromised root access? That could explain the privileged users.
upvoted 0 times
...
Rashad
5 months ago
Agreed, the timing is suspicious.
upvoted 0 times
...
Wava
5 months ago
I think it's A) compromised insider. Sounds like an inside job.
upvoted 0 times
...
Ocie
5 months ago
Not sure, this could be a false flag too.
upvoted 0 times
...
Elli
6 months ago
I agree, the timing with the network traffic is suspicious.
upvoted 0 times
...
Irma
6 months ago
Wait, could it be compromised root access instead?
upvoted 0 times
...
Annice
6 months ago
Definitely A) compromised insider.
upvoted 0 times
...
Billy
7 months ago
Sounds like a compromised insider situation.
upvoted 0 times
...
Danica
7 months ago
I'm going with compromised insider. Those privileged users are probably up to no good, and the network traffic is the smoking gun.
upvoted 0 times
...
Delbert
7 months ago
Haha, I bet the engineer is just trying to cover up their own compromised root access. Classic IT shenanigans!
upvoted 0 times
...
Laquita
7 months ago
Nah, this is clearly a compromised network. Those suspicious activities are probably coming from outside the organization.
upvoted 0 times
...
Brittni
7 months ago
I'd say it's a compromised database table. Those privileged users could be accessing sensitive data without authorization.
upvoted 0 times
...
Ma
7 months ago
Hmm, this seems like a classic case of a compromised insider. The suspicious usernames and network traffic are definitely red flags.
upvoted 0 times
...
Zena
8 months ago
This reminds me of a practice question where we discussed network anomalies linked to user accounts. I wonder if compromised network might be the right answer?
upvoted 0 times
...
Daryl
8 months ago
I'm not entirely sure, but I think compromised root access could also fit if those users have elevated privileges. It’s tricky!
upvoted 0 times
...
Phil
8 months ago
I remember studying about compromised insiders, especially in relation to suspicious usernames in active directories. That seems like a strong possibility here.
upvoted 0 times
...
Barney
8 months ago
Ah, I see what's going on here. The suspicious user creation and network traffic point to a compromised insider. I'm confident option A is the correct answer.
upvoted 0 times
...
Ashley
8 months ago
This seems like a good opportunity to apply some of the incident response strategies we've been practicing. I'll methodically analyze the evidence and consider the different attack vectors before selecting my answer.
upvoted 0 times
...
Buddy
8 months ago
I'm a bit confused on this one. The question mentions database tables, but the options don't seem to directly match that. I'll need to re-read the details and see if I can eliminate some of the options.
upvoted 0 times
...
Chara
9 months ago
I still believe A) is the best choice. Insider threats are tricky!
upvoted 0 times
...
Dacia
9 months ago
I feel like the creation date matching suspicious traffic points more towards a compromised insider scenario. That’s what we practiced last week!
upvoted 0 times
...
Graciela
9 months ago
Okay, let's see here. Suspicious usernames, privileged access, and network traffic - that sounds like a compromised insider situation to me. I'll go with option A.
upvoted 0 times
...
Wayne
10 months ago
Hmm, this seems like a tricky one. I'll need to carefully review the details in the exhibit and think through the potential types of compromise.
upvoted 0 times
Owen
4 months ago
I still lean towards compromised insider. It fits the scenario.
upvoted 0 times
...
Nicholle
4 months ago
True, that could indicate compromised network access.
upvoted 0 times
...
Elroy
4 months ago
But what about the network traffic?
upvoted 0 times
...
Winifred
9 months ago
Agreed, the usernames seem suspicious.
upvoted 0 times
...
Brent
9 months ago
I think it's a compromised insider situation.
upvoted 0 times
...
...

Save Cancel