These questions describe a network symptom and ask you to identify the root cause or the correct fix. They appear across all certification exams and reward systematic thinking over memorisation. The best candidates follow a consistent troubleshooting framework even under time pressure.
Start Scenario PracticeAn organization's security policy mandates that all external media (USB drives, external hard drives) must be scanned for malware before use. An employee inserts a USB drive to transfer a presentation for a meeting. The employee runs the antivirus scan, but it fails to complete because the USB drive has a hardware write-protect switch. The employee is in a hurry. What should the employee do?
Explanation: The security policy mandates scanning all external media before use. Because the USB drive has hardware write-protect, the antivirus scan cannot complete. Therefore, the employee should not use this USB drive and should instead use an alternative approved method (e.g., network share, email, or cloud storage) to transfer the file. This ensures compliance with the policy. Option A is incorrect because manually checking file extensions does not replace a proper malware scan. Option C is incorrect because disabling write protection may compromise security and the scan still might not be reliable. Option D is incorrect because bypassing the scan violates the policy.
A SOC analyst is reviewing a large number of alerts from a SIEM. Which THREE of the following are effective steps to prioritize and investigate alerts in a high-volume environment? (Choose three.)
Explanation: Prioritizing by severity, correlating with threat intelligence, and checking for associated IoCs help focus on important alerts. Alert fatigue leads to missed incidents; automation and triage are key.
A company's web server is overwhelmed with traffic from many compromised devices, causing legitimate users to be unable to access the site. What type of attack is this?
Explanation: A DDoS uses multiple sources to flood a target, making it unavailable.
You are a security analyst at a medium-sized company. The company uses a SIEM that collects logs from firewalls, IDS/IPS, and endpoint detection and response (EDR) agents. You receive an alert that a user's workstation (IP 10.0.1.25) has been making outbound connections to an IP address (198.51.100.10) on port 4444 (commonly used by malware). The alert includes a SIEM correlation rule that triggered when three or more connections to that IP occurred within 5 minutes. You check the EDR logs and see that the workstation is running a process named 'svchost.exe' that is connecting to that IP. The process path is C:\Windows\system32\svchost.exe, which is legitimate. However, you notice that the process has a digital signature from 'Microsoft Corporation', but the signature date is from 2021. The workstation's operating system is Windows 10 22H2, fully patched as of last month. The user reports that they have been experiencing slow performance and occasional pop-ups. Which action should you take FIRST to investigate this potential compromise?
Explanation: The presence of a legitimate svchost.exe with a valid Microsoft signature does not rule out DLL sideloading or injection. By listing all DLLs loaded by the process, you can identify suspicious non-Microsoft DLLs that may be executing malicious code within the trusted svchost.exe context, which is a common technique used by malware to evade detection.
A Windows analyst uses Process Explorer to investigate parent-child relationships. Which TWO characteristics are commonly associated with malicious processes?
Explanation: Malware often spawns child processes from unusual parents (e.g., Microsoft Word spawning cmd.exe) and may have suspicious command-line arguments.
+4 more scenario questions available
Practice all Troubleshooting Scenario QuestionsThese questions describe a network symptom and ask you to identify the root cause or the correct fix. They appear across all certification exams and reward systematic thinking over memorisation. The best candidates follow a consistent troubleshooting framework even under time pressure. These appear throughout the 200-201 and require you to apply your knowledge, not just recall facts.
Cisco doesn't publish an exact breakdown, but scenario-based questions (especially exhibit and command-output formats) make up a significant portion of the 200-201. Practicing each scenario type ensures you're ready for any format.
Yes. Courseiva provides free 200-201 scenario practice across all official exam domains. The platform includes scenario-based questions, command-output interpretation, topic-based practice, mock exams, and readiness tracking — no account required.
Launch a full Troubleshooting Scenario Questions session with instant scoring and detailed explanations.
Start Scenario Practice →