Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.
Start Scenario PracticeAn analyst is investigating a Windows host and observes a suspicious process with PID 1337. Which THREE of the following Volatility commands would provide useful information about this process? (Choose three.)
Explanation: The `cmdline` plugin displays the command-line arguments used to start a process, which is critical for identifying malicious or suspicious execution patterns (e.g., obfuscated paths, encoded commands). For PID 1337, this reveals exactly how the process was launched, helping to confirm or refute malicious intent.
An analyst is investigating a Windows host that likely has malware persistence via the registry. Which TWO registry hives are commonly used to store Run keys for user logon persistence? (Select 2)
Explanation: The Run keys under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run are standard locations where Windows executes programs automatically at user logon. Malware commonly writes entries to these keys to achieve persistence, making them critical for host-based analysis.
Which THREE are typical sources of log data used in security monitoring? (Choose three.)
Explanation: Windows Event Logs are a primary source of security monitoring data because they record critical security events such as logon attempts, account changes, and process creation (Event IDs 4624, 4625, 4688). Security Information and Event Management (SIEM) systems ingest these logs to detect unauthorized access, privilege escalation, and malware execution.
A security policy mandates that all network devices must be hardened. Which THREE of the following are common hardening best practices for routers and switches? (Select three.)
Explanation: Option A is correct because implementing access control lists (ACLs) on routers and switches restricts which traffic is permitted to reach the management plane and transit the device, enforcing least-privilege filtering as a core hardening control. Option B is correct because disabling unused services (for example, CDP, LLDP, HTTP server, or unused routing protocols) reduces the attack surface by eliminating unnecessary listening ports and daemons that could be exploited. Option E is correct because SNMPv3 with strong authentication (authNoPriv or authPriv using SHA and AES) replaces insecure SNMPv1/v2c community strings with encrypted, authenticated management traffic. Option C is not a hardening practice because Telnet transmits credentials and session data in cleartext; SSH should be used instead. Option D is not a hardening practice because default credentials are widely known and must be changed immediately during initial setup.
A security analyst is configuring a firewall to block common reconnaissance techniques. Which THREE types of reconnaissance traffic should be blocked to prevent active reconnaissance? (Choose three.)
Explanation: Vulnerability scanning (C) is active reconnaissance because the attacker directly sends probes to the target to identify weaknesses, generating traffic the firewall can detect and block. Port scanning (D) is active reconnaissance since tools like Nmap send TCP SYN, FIN, or UDP packets to enumerate open ports on the target hosts. Ping sweeps (E) are active reconnaissance because ICMP Echo Request packets are sent across an address range to discover live hosts. WHOIS lookups (B) are passive reconnaissance, as they query public registration databases rather than the target's own systems, so a firewall cannot block them. Social engineering (A) is a human-based attack that involves no network traffic to the firewall and is therefore not a reconnaissance traffic type to filter.
+15 more scenario questions available
Practice all Select Two (Multi-Select) QuestionsMulti-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination. These appear throughout the 200-201 and require you to apply your knowledge, not just recall facts.
Cisco doesn't publish an exact breakdown, but scenario-based questions (especially exhibit and command-output formats) make up a significant portion of the 200-201. Practicing each scenario type ensures you're ready for any format.
Yes. Courseiva provides free 200-201 scenario practice across all official exam domains. The platform includes scenario-based questions, command-output interpretation, topic-based practice, mock exams, and readiness tracking — no account required.
Launch a full Select Two (Multi-Select) Questions session with instant scoring and detailed explanations.
Start Scenario Practice →