Cisco · Free Practice Questions · Last reviewed May 2026
30real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
25% of exam · 6 sample questions below
An analyst is monitoring network traffic and observes a large number of TCP SYN packets sent to a single host on various ports with no corresponding SYN-ACK replies. This behavior is most indicative of which type of attack?
ARP spoofing
DNS amplification attack
ICMP flood attack
SYN flood attack
SYN packets to varied ports with no SYN-ACK replies indicate half-open connections exhausting the target's backlog queue. This matches a SYN flood, a volumetric denial-of-service attack that never completes the TCP handshake, distinguishing it from port scans that typically elicit RST responses.
A security engineer is setting up a Snort rule to detect FTP traffic where the source IP is not from the internal network. Which Snort rule header correctly specifies the action, protocol, source, and destination?
alert tcp !$HOME_NET any -> any 21
The `!$HOME_NET` negation operator matches any source outside the defined internal network, satisfying the "not from the internal network" constraint. `alert tcp` sets the action and protocol, `any` covers all source ports, and `-> any 21` targets FTP destination port 21 on any host.
alert tcp $HOME_NET any -> any 21
alert tcp any any -> any 21
alert udp any any -> any 21
An analyst is examining a firewall log entry: '2023-10-25 14:30:00 ACTION=DENY SRC=10.0.0.5 DST=203.0.113.50 PROTO=TCP SPT=445 DPT=445'. Which statement best describes this event?
An internal host attempted to establish an SMB connection to an external IP and was blocked.
Port 445 is SMB, and the DENY action confirms the firewall dropped the session. The log shows an internal host (10.0.0.5) initiating TCP/445 toward an external address, so the outbound SMB connection attempt was blocked.
A DNS query was made from an internal host to an external server.
An external host attempted to access an internal SMB server on port 445 and was blocked.
An internal host successfully connected to an external server on port 445.
A SOC analyst needs to create a SIEM correlation rule to detect a brute force attack against SSH on a server. Which of the following would be the most effective rule logic?
Alert when a single failed SSH login occurs.
Alert when more than 10 failed SSH logins from the same source IP occur within 1 minute.
Thresholding failed SSH logins by source IP within a one-minute window captures the high-frequency, single-origin pattern characteristic of brute forcing, while the short window and IP grouping suppress unrelated sporadic failures. This matches the stem's SSH brute force scenario.
Alert when successful SSH logins occur outside business hours.
Alert when multiple failed SSH logins from various IPs occur in one hour.
A security analyst is reviewing Zeek connection logs and sees the following entry: '192.168.1.10:12345 > 10.0.0.1:80 (tcp) duration 0.001 sec, service http, bytes 60, state S0'. Based on the state 'S0', what does this indicate about the connection?
Data was transferred successfully and the connection closed normally.
A SYN packet was sent but no reply was received.
Zeek's S0 state records a connection attempt where the originator sent a SYN but received no SYN-ACK, so the handshake never completed. This matches the stem's unanswered SYN, distinguishing it from established (SF) or reset (RST) states.
The connection was established successfully.
The connection was reset by the remote host.
An analyst receives an IDS alert with signature name 'ET TROJAN Win32.Zeus Checkin' and severity 'high'. The alert shows source IP 192.168.1.50 and destination IP 198.51.100.20 on port 443. Which action should the analyst take FIRST?
Isolate the source host from the network to prevent further communication.
The signature indicates an active Zeus trojan check-in from internal host 192.168.1.50 to external infrastructure over port 443, confirming likely compromise and command-and-control beaconing. Isolating that host immediately halts exfiltration and lateral movement, the priority containment step before deeper forensic analysis.
Check the host's web browsing history for suspicious websites.
Immediately block the destination IP on the firewall.
Ignore the alert because the traffic is encrypted over port 443.
Want more Security Monitoring practice?
Practice this domain15% of exam · 6 sample questions below
During which phase of the NIST SP 800-61 Rev 2 incident response process should an organization develop and exercise the incident response plan?
Preparation
Preparation is the phase where organisations build incident response capability before incidents occur, including developing the plan, defining roles, and conducting exercises. NIST SP 800-61 Rev 2 places plan creation and training squarely here, satisfying the stem's requirement to both develop and exercise the plan ahead of any detection or containment activity.
Post-Incident Activity
Detection and Analysis
Containment, Eradication, and Recovery
A security analyst receives an alert from the SIEM indicating a large number of failed login attempts from an external IP address targeting a user account. According to the incident response process, what should be the analyst's first action?
Initiate the legal hold process to preserve evidence
Contain the threat by blocking the IP address on the firewall
Escalate the alert to Tier 2 for deeper investigation
Perform initial triage to determine the severity and validity
Triage validates whether the alert is a genuine attack or a false positive and assigns severity before escalation or containment. Acting on unverified SIEM data risks wasted effort or disrupting legitimate activity, so initial triage must precede deeper investigation, containment, or notification.
An organization's incident response team has identified a malware infection on a critical server. They need to collect evidence for potential legal action. Which of the following is the most important step to ensure the admissibility of the evidence?
Contacting legal counsel before proceeding
Documenting the chain of custody for all evidence
Chain-of-custody documentation records every transfer, handler and storage condition of the seized media, proving the evidence was not altered or tampered with. Without this unbroken audit trail, courts may rule the malware artefacts inadmissible, regardless of how technically sound the forensic acquisition itself was.
Creating a forensic image of the affected hard drive
Isolating the server from the network
Which role in the incident response process is primarily responsible for determining the business impact of an incident and making strategic decisions?
HR
Legal counsel
Incident handler
CISO
The CISO owns strategic incident decisions and business-impact assessment, translating technical findings into organisational risk. This role authorises containment, notification and recovery priorities, satisfying the stem's requirement for strategic decision-making authority rather than hands-on triage performed by analysts or the IR lead.
An employee is suspected of using company resources to access inappropriate websites. Which security policy most directly addresses this behavior?
Acceptable Use Policy (AUP)
An Acceptable Use Policy defines permitted employee use of company systems and networks, explicitly prohibiting access to inappropriate websites. It directly governs the behaviour described, making it the policy that addresses misuse of company resources for browsing inappropriate content.
Remote access policy
Information security policy
Password policy
During a risk assessment, a company identifies that the annualized loss expectancy (ALE) for a specific threat is $50,000. The cost to implement a mitigation control is $30,000 with an annual maintenance cost of $5,000. According to risk management principles, what is the most appropriate risk treatment option?
Accept the risk because the mitigation cost is higher than the ALE
Avoid the risk by discontinuing the activity
Transfer the risk by purchasing cyber insurance
Mitigate the risk by implementing the control
The control's total annual cost is $35,000, which is lower than the $50,000 ALE, so mitigation yields a positive return and reduces expected loss. This satisfies the risk management principle of selecting treatment where control cost is less than the annualised loss expectancy.
Want more Security Policies and Procedures practice?
Practice this domain20% of exam · 6 sample questions below
During a network intrusion analysis, a security analyst observes repeated TCP SYN packets sent to a range of ports on a target host, each followed by an RST response. No subsequent ACK packets are observed. Which phase of the Cyber Kill Chain is the attacker most likely executing?
Reconnaissance
SYN packets followed by RST responses, with no completed handshake, indicate a port scan probing which ports are open or closed. This information-gathering activity against the target host characterises the Reconnaissance phase of the Cyber Kill Chain.
Delivery
Weaponization
Exploitation
An analyst reviewing network alerts notices a rule triggered for 'ET SCAN NMAP -sU scan' based on traffic to a Linux server. The packet capture shows multiple UDP packets to various ports, and for closed ports, the server responds with ICMP Destination Unreachable (Port Unreachable). Which type of scan is being performed, and how should the analyst classify this alert?
TCP SYN scan; true positive
UDP scan; true positive
Nmap's UDP scan sends zero-byte UDP datagrams to target ports; closed ports return ICMP port unreachable, matching the capture. The rule signature and traffic genuinely reflect scanning activity, so the analyst classifies it as a true positive rather than a false positive.
UDP scan; false positive
TCP connect scan; true negative
A security analyst is investigating an alert that indicates a potential SQL injection attack. Which of the following HTTP request patterns is most indicative of a SQL injection attempt?
GET /login?user=admin&pass=password123
GET /search?q=<script>alert('XSS')</script>
GET /products?id=1 UNION SELECT * FROM users
The UNION SELECT payload is injected directly into the id parameter, attempting to append rows from the users table to the query result. This satisfies the SQL injection indicator, unlike plain numeric values or encoded characters that carry no SQL syntax.
GET /index.html HTTP/1.1
An analyst detects traffic from an internal host that periodically sends small DNS queries to a domain with high entropy subdomains (e.g., 'a3k9f2.example.com'). The domain is not on any blocklist, and the query intervals are consistent every 60 seconds. Which technique is most likely being used?
DNS tunnelling for C2 communication
High-entropy subdomains carrying small queries at fixed 60-second intervals indicate data encoded into DNS labels and exfiltrated or commanded through recursive resolvers. The absence from blocklists and regular beaconing fit DNS tunnelling used for command-and-control rather than normal resolution.
DNS amplification attack
Normal DNS resolution for a dynamic DNS service
DNS cache poisoning attempt
An analyst is investigating lateral movement and observes SMB authentication attempts from host A to multiple other hosts using NTLM authentication with a hash value instead of a password. Which attack technique is most likely being used?
Pass-the-hash attack
Pass-the-hash exploits NTLM's design, where the password hash itself authenticates without knowing the plaintext. Replaying a captured hash across multiple hosts via SMB produces exactly the observed pattern of lateral authentication attempts, distinguishing it from credential guessing or Kerberos abuse.
Brute force attack
Kerberos golden ticket attack
SMB relay attack
An intrusion detection system alerts on traffic that appears to be a command and control (C2) beacon. Which of the following characteristics is most typical of beaconing traffic?
Large data transfers to a known cloud provider
ICMP echo requests to multiple hosts
Random intervals with varying packet sizes
Periodic connections at regular intervals to an external IP
Beaconing malware checks in with its command and control server on a fixed schedule, producing repeated connections to the same external IP at consistent intervals. This regularity, rather than payload content or port choice, is the defining signature analysts use to distinguish beaconing from normal traffic.
Want more Network Intrusion Analysis practice?
Practice this domain20% of exam · 6 sample questions below
A security analyst is analyzing a suspicious PE file. Using a hex editor, the analyst sees the MZ header (4D 5A). The file's entropy is calculated as 7.8. What does the high entropy most likely indicate?
The file is a legitimate signed binary
The file is likely packed or obfuscated
Entropy near 7.8 approaches the theoretical maximum for byte data, indicating compressed or encrypted content rather than readable code. Packers and obfuscators compress or encrypt the payload, so high entropy in a PE file suggests packing.
The file is corrupted
The file contains mostly plain text strings
A Linux administrator checks authentication logs to investigate a possible brute-force attack. Which log file typically contains records of successful and failed SSH login attempts?
/var/log/kern.log
/var/log/auth.log
/var/log/auth.log records PAM authentication events on Debian-based Linux systems, capturing both successful and failed SSH login attempts with source addresses and usernames. This directly satisfies the stem's requirement to investigate brute-force activity, since repeated failures from one origin become visible there.
/var/log/messages
/var/log/syslog
A Windows Event Log shows Event ID 4625 multiple times from the same source IP address. What type of activity does this indicate?
Failed logon attempts indicating a possible brute-force attack
Event ID 4625 is logged whenever a logon attempt fails, and repeated occurrences from one source IP address indicate sustained authentication failures consistent with brute-force activity. This directly satisfies the stem's constraint of multiple 4625 events from the same source, distinguishing it from successful logons (4624) or lockouts (4740).
Successful logon after multiple attempts
Credential validation by a domain controller
A user account was created
An analyst is examining a suspicious file that appears to be a PDF but when checking the magic bytes at offset 0, sees '50 4B 03 04'. What does this indicate?
The file is a genuine PDF file
The file is a plain text file
The file is a ZIP archive
The magic bytes 50 4B 03 04 are the ZIP local file header signature ('PK\x03\x04'). Despite the .pdf extension, the file's actual container format is ZIP, which is typical of Office documents and JAR archives and indicates the extension has been spoofed.
The file is an executable
An analyst uses 'sc query' on a Windows host and finds a service named 'WindowsUpdate' with a binary path pointing to 'C:\Users\Public\update.exe'. The service is running. Why is this suspicious?
The service is running
The service name is misspelled
The service displays 'WindowsUpdate'
The binary path is not in a system directory
Legitimate Windows services almost always execute from protected system locations such as C:\Windows\System32, not user-writable directories. C:\Users\Public is world-writable, allowing any local user to replace update.exe and gain persistence with SYSTEM privileges, since the service runs under a privileged account. This path anomaly satisfies the stem's suspicion constraint.
Which Windows artifact stores evidence of file execution, including the path and run count, and is located in C:\Windows\Prefetch?
Windows Event Logs
Registry hives
Scheduled tasks
Prefetch files
Prefetch files, stored in C:\Windows\Prefetch with a .pf extension, record executable name, file path, run count and last-run timestamps. This directly satisfies the stem's requirement for an artifact evidencing file execution with path and run count.
Want more Host-Based Analysis practice?
Practice this domainWhich element of the CIA triad is primarily concerned with preventing unauthorized access to data?
Non-repudiation
Integrity
Confidentiality
Confidentiality guards data against disclosure to unauthorised parties, directly satisfying the stem's requirement to prevent unauthorised access. It achieves this through encryption, access controls and classification, unlike Integrity, which addresses unauthorised modification, or Availability, which addresses timely, reliable access for legitimate users.
Availability
A security analyst discovers that a malicious actor is using a technique to gather information about employees by searching social media sites. Which type of attack is being performed?
Active reconnaissance
Passive reconnaissance
Searching social media for employee details involves no direct interaction with the target's systems, so nothing is sent that could trigger detection. That absence of engagement with the target's infrastructure is precisely what makes it passive reconnaissance rather than active scanning.
Denial of Service
Social engineering
Which of the following best describes a vulnerability?
A weakness in a system that could be exploited
A vulnerability is precisely a weakness or flaw in a system that an attacker could exploit to violate confidentiality, integrity or availability; this definition distinguishes it from a threat, which is the potential cause of harm.
The act of taking advantage of a weakness
The likelihood that a threat will exploit a weakness
A potential event that could cause harm
An organization experiences a ransomware attack where files are encrypted and a ransom is demanded. Which element of the CIA triad is most directly impacted?
Availability
Ransomware encryption renders files unreadable, directly denying legitimate access to data and systems. Availability is the CIA element concerned with ensuring authorised users can access resources when required, so encryption that blocks access satisfies the stem's constraint of disrupted data access. Confidentiality and integrity remain intact; the data is neither exposed nor altered.
Integrity
Non-repudiation
Confidentiality
A security analyst is examining a log file and notices that the hash value of a configuration file does not match the expected value. Which security goal has been violated?
Integrity
A mismatched hash directly evidences unauthorised modification of the configuration file, violating integrity. Hashing detects any alteration to data, so comparing the computed digest against the expected baseline value confirms the file's contents changed. Confidentiality and availability remain unaffected, as neither the file's secrecy nor its accessibility is implicated by the discrepancy.
Confidentiality
Non-repudiation
Availability
Which of the following is an example of a symmetric encryption algorithm?
SHA-256
RSA
AES
AES is a symmetric block cipher using the same secret key for encryption and decryption, satisfying the stem's requirement for a symmetric algorithm. Operating on 128-bit blocks with key sizes of 128, 192, or 256 bits, it contrasts with asymmetric algorithms such as RSA, which use separate public and private keys.
ECC
Want more Security Concepts practice?
Practice this domainThe 200-201 exam has 95 questions and must be completed in 120 minutes. Cisco passing scores vary by exam version and are not always publicly listed. Check the official Cisco exam page before booking.
CLI output interpretation, network topology analysis, routing behaviour, switching concepts, troubleshooting, and configuration questions.
The exam covers 5 domains: Security Monitoring, Security Policies and Procedures, Network Intrusion Analysis, Host-Based Analysis, Security Concepts. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Cisco 200-201 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.