Reinforce 200-201 concepts with active-recall study cards covering all 5 blueprint domains. Each card shows the question on the front and the correct answer with a full explanation on the back.
Flashcards work through active recall — the process of retrieving information from memory rather than passively re-reading it. Research consistently shows that active recall produces stronger, longer-lasting memory than re-reading study guides. For 200-201 preparation, this means flashcards are one of the highest-return study tools available.
Attempt recall first
Read the 200-201 question on each card, pause, and attempt to formulate the answer in your own words before revealing. This retrieval attempt — even if wrong — dramatically strengthens memory compared to immediately reading the answer.
Review wrong cards again
When you get a card wrong, note it and add it back to your review pile. Spaced repetition — seeing difficult cards more frequently — is the mechanism that makes flashcard study far more efficient than linear reading.
Study by domain
Group your 200-201 flashcard sessions by domain for the first 3–4 weeks. Master one domain before moving to the next. In the final week, shuffle all cards together to test cross-domain recall — which is what the real 200-201 exam requires.
Short sessions beat marathon reviews
20–30 flashcard cards per session, done daily, produces better retention than a single 200-card marathon session. Five short daily sessions per week over 4 weeks gives you over 400 total card reviews — enough to reliably pass 200-201.
Sample cards from the 200-201 flashcard bank. Read the question, think of the answer, then read the explanation below.
An analyst is monitoring network traffic and observes a large number of TCP SYN packets sent to a single host on various ports with no corresponding SYN-ACK replies. This behavior is most indicative of which type of attack?
SYN flood attack
A large volume of TCP SYN packets to a single host across various ports with no SYN-ACK replies is the classic signature of a SYN flood attack. The attacker sends many SYN packets (often with spoofed source IPs) to exhaust the target's half-open connection table, preventing legitimate connections from completing the TCP three-way handshake.
A security engineer is setting up a Snort rule to detect FTP traffic where the source IP is not from the internal network. Which Snort rule header correctly specifies the action, protocol, source, and destination?
alert tcp !$HOME_NET any -> any 21
The rule header alert tcp !$HOME_NET any -> any 21 correctly specifies: action (alert), protocol (tcp), source (!$HOME_NET, i.e., NOT the internal network), source port (any), direction (->), destination (any), and destination port (21, FTP). The ! negation operator inverts the HOME_NET variable, so the rule fires only when the source is external — exactly what the engineer wants.
An analyst is examining a firewall log entry: '2023-10-25 14:30:00 ACTION=DENY SRC=10.0.0.5 DST=203.0.113.50 PROTO=TCP SPT=445 DPT=445'. Which statement best describes this event?
An internal host attempted to establish an SMB connection to an external IP and was blocked.
The log entry shows a deny action for traffic from internal IP 10.0.0.5 to external IP 203.0.113.50 on TCP port 445, which is the default port for SMB (Server Message Block) protocol. Since the source is internal (RFC 1918 address) and the destination is external, this indicates an outbound connection attempt that was blocked by the firewall. SMB is commonly used for file sharing and is often restricted outbound to prevent data exfiltration or malware propagation.
A SOC analyst needs to create a SIEM correlation rule to detect a brute force attack against SSH on a server. Which of the following would be the most effective rule logic?
Alert when more than 10 failed SSH logins from the same source IP occur within 1 minute.
A brute force attack is characterized by a high volume of failed authentication attempts from a single source within a short time window. By alerting on more than 10 failed SSH logins from the same source IP within 1 minute, the rule effectively distinguishes malicious automated guessing from isolated user errors, minimizing false positives while capturing the core behavior of a brute force attempt.
During which phase of the NIST SP 800-61 Rev 2 incident response process should an organization develop and exercise the incident response plan?
Preparation
The Preparation phase of NIST SP 800-61 Rev 2 covers establishing the incident response capability, including developing the IR plan, acquiring tools, training staff, and exercising the plan through tabletop and functional exercises. Exercising the plan before an incident occurs is explicitly a Preparation activity, not something done during or after an event.
A security analyst receives an alert from the SIEM indicating a large number of failed login attempts from an external IP address targeting a user account. According to the incident response process, what should be the analyst's first action?
Perform initial triage to determine the severity and validity
Initial triage is part of Detection and Analysis to determine if the alert is a true positive and assess its priority.
During a network intrusion analysis, a security analyst observes repeated TCP SYN packets sent to a range of ports on a target host, each followed by an RST response. No subsequent ACK packets are observed. Which phase of the Cyber Kill Chain is the attacker most likely executing?
Reconnaissance
Repeated TCP SYN packets to multiple ports followed by RST responses indicate a port scan, which is a hallmark of the Reconnaissance phase of the Cyber Kill Chain. The attacker is probing for open ports and services without completing the TCP handshake, which is typical of a SYN stealth scan. This activity occurs before any exploitation or delivery.
An analyst reviewing network alerts notices a rule triggered for 'ET SCAN NMAP -sU scan' based on traffic to a Linux server. The packet capture shows multiple UDP packets to various ports, and for closed ports, the server responds with ICMP Destination Unreachable (Port Unreachable). Which type of scan is being performed, and how should the analyst classify this alert?
UDP scan; true positive
UDP scans send UDP packets; closed ports respond with ICMP Port Unreachable. This matches the alert signature, indicating a true positive for a UDP scan.
A security analyst is investigating an alert that indicates a potential SQL injection attack. Which of the following HTTP request patterns is most indicative of a SQL injection attempt?
GET /products?id=1 UNION SELECT * FROM users
The UNION SELECT payload is the classic SQL injection signature: it appends a second SELECT statement to the original query, allowing the attacker to retrieve data from other tables such as 'users'. The presence of SQL keywords (UNION, SELECT, FROM) inside a URL parameter that should only contain a numeric ID is a strong indicator of SQLi. This pattern targets the backend database directly, unlike script tags which target the browser.
A security analyst is analyzing a suspicious PE file. Using a hex editor, the analyst sees the MZ header (4D 5A). The file's entropy is calculated as 7.8. What does the high entropy most likely indicate?
The file is likely packed or obfuscated
High entropy (close to 8) suggests the file is packed or encrypted, as compressed or encrypted data has high randomness. This is often used by malware to evade signature detection.
A Linux administrator checks authentication logs to investigate a possible brute-force attack. Which log file typically contains records of successful and failed SSH login attempts?
/var/log/auth.log
On Debian/Ubuntu Linux systems, /var/log/auth.log records authentication-related events including successful and failed SSH logins, sudo usage, and PAM activity. It is the primary log file for investigating brute-force attacks against SSH. This matches the question's requirement.
A Windows Event Log shows Event ID 4625 multiple times from the same source IP address. What type of activity does this indicate?
Failed logon attempts indicating a possible brute-force attack
Event ID 4625 indicates a failed logon attempt. Multiple failures from the same source suggest a brute-force attack.
Which element of the CIA triad is primarily concerned with preventing unauthorized access to data?
Confidentiality
Confidentiality is the CIA triad element that ensures data is accessible only to authorized users. It is primarily enforced through encryption (e.g., AES-256 for data at rest, TLS 1.3 for data in transit) and access control mechanisms (e.g., RBAC, ACLs). Preventing unauthorized access directly aligns with confidentiality's goal of protecting data from disclosure.
A security analyst discovers that a malicious actor is using a technique to gather information about employees by searching social media sites. Which type of attack is being performed?
Passive reconnaissance
Passive reconnaissance involves gathering information about a target without directly interacting with its systems, such as searching public social media sites for employee details. Because the attacker only observes publicly available data and does not send packets or queries to the target's infrastructure, it is classified as passive. This contrasts with active reconnaissance, which involves direct interaction (e.g., port scanning).
Which of the following best describes a vulnerability?
A weakness in a system that could be exploited
A vulnerability is a flaw or weakness in a system's design, implementation, or configuration that can be exploited by a threat actor. Option A correctly captures this as a weakness that could be exploited, which aligns with the standard definition in cybersecurity (e.g., NIST SP 800-30). It is not the act of exploitation itself, nor the likelihood of exploitation, nor the potential event causing harm.
The 200-201 flashcard bank covers all 5 official blueprint domains published by Cisco. Cards are distributed proportionally, so domains with higher exam weight have more cards.
Domain Coverage
Security Monitoring
Security Policies and Procedures
Network Intrusion Analysis
Host-Based Analysis
Security Concepts
Both flashcards and practice questions are evidence-based study tools. The difference is in what they train:
Flashcards — concept retention
Best for memorising definitions, acronyms, protocol behaviours, command syntax, and conceptual distinctions. Use flashcards to build the foundational vocabulary that 200-201 questions assume you know.
Best in: weeks 1–3
Practice tests — application
Best for applying concepts to realistic scenarios, eliminating distractors, and building exam stamina.200-201 questions test scenario reasoning — not just recall — so practice tests are essential.
Best in: weeks 3–6
The most effective 200-201 study plan combines both: use flashcards for the first 2–3 weeks to build conceptual foundations, then shift to practice tests and mock exams in the final 2–3 weeks to apply and benchmark that knowledge. Most candidates who pass on their first attempt use both tools.
Yes. Courseiva provides free 200-201 flashcards across all official exam domains. Every card includes the correct answer and a full explanation of why it is right and why the distractors are wrong. The platform also includes topic-based practice, mock exams, and readiness tracking — no account required.
Courseiva has 968+ original 200-201 flashcards across all 5 exam blueprint domains. New cards are added regularly as the question bank grows. All cards are checked against the official Cisco exam objectives, with editorial oversight from an experienced network and security engineer.
Courseiva flashcards are purpose-built for IT certification exams. Unlike generic flashcard platforms where content quality varies, every Courseiva card is mapped to the official 200-201 exam blueprint, written by engineers who hold the certification, and includes a full explanation of the correct answer and why the distractors are wrong. This explanation quality is what separates genuine learning from rote memorisation.
Courseiva is a web platform — an internet connection is required. For offline study, we recommend creating free Courseiva account, using the platform in your browser, and using your device's offline capabilities if your browser supports offline web apps.
Save your results, see which domains need more work, and get spaced repetition recommendations — all free.
Sign Up FreeFree forever · Every certification included