20+ practice questions focused on Network Intrusion Analysis — one of the most tested topics on the Cisco CyberOps Associate 200-201 exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Network Intrusion Analysis PracticeDuring an incident response, an analyst extracts a file from a PCAP using Wireshark's 'Export Objects' feature. The file contains shellcode that uses NOP sleds and encodes a reverse shell command. Which Cyber Kill Chain phase does this file represent?
Explanation: The file contains shellcode and is extracted from network traffic, indicating it was delivered to the target. This aligns with the delivery phase.
A network analyst is examining a PCAP file and applies the Wireshark display filter 'http.request'. The results show several POST requests to '/login.php' with parameters containing 'username=admin&password=secret'. What type of attack is indicated?
Explanation: The filter 'http.request' isolates HTTP request packets, and the captured POST requests to '/login.php' contain cleartext credentials ('username=admin&password=secret'). This indicates that login credentials are being transmitted in plaintext over HTTP, which is characteristic of credential theft via phishing or an unencrypted login form. The presence of a single successful-looking credential pair (admin/secret) rather than many failed attempts points to stolen credentials being submitted, not a brute-force or injection attack.
A security analyst is investigating a suspected data exfiltration incident. Which TWO of the following indicators are most consistent with exfiltration over DNS?
Explanation: Option A is correct because DNS tunneling tools such as iodine and dnscat2 encode stolen data in TXT records, and unusually large TXT responses (often exceeding the typical ~255-byte string limit or padded to hundreds of bytes) are a classic signature of data being returned or acknowledged over DNS. Option E is correct because exfiltration over DNS relies on many queries to a single attacker-controlled domain, and the encoded payloads are placed in random-looking subdomains (e.g., base32/base64 labels) to smuggle data out while evading detection. Option B does not belong because ICMP echo requests are typical of ping sweeps or ICMP tunneling, not DNS-based exfiltration. Option C does not belong because consistent traffic to a C2 server on port 443 indicates HTTPS command-and-control, not DNS exfiltration. Option D does not belong because failed HTTP POST requests to a file-sharing site suggest attempted web uploads or blocked exfiltration over HTTP, not DNS.
An analyst is analyzing a PCAP from a compromised host. Which THREE of the following are common indicators of exploitation attempts in network traffic?
Explanation: Exploitation indicators include shellcode patterns (NOP sleds, ROP gadgets) and heap spray (large blocks of similar data).
An analyst captures traffic and sees a TCP connection with only a SYN packet and an RST response. No SYN-ACK is observed. Which scan technique is this?
Explanation: A SYN scan sends a SYN and expects a SYN-ACK; if an RST is received, the port is closed. Incomplete handshake without SYN-ACK indicates a half-open scan.
+15 more Network Intrusion Analysis questions available
Practice all Network Intrusion Analysis questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Network Intrusion Analysis. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Network Intrusion Analysis questions on the 200-201 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Network Intrusion Analysis is tested as part of the Cisco CyberOps Associate 200-201 blueprint. Practicing with targeted Network Intrusion Analysis questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free 200-201 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Network Intrusion Analysis is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Network Intrusion Analysis practice session with instant scoring and detailed explanations.
Start Network Intrusion Analysis Practice →