Courseiva

200-201 · domain

Security Concepts

Security Concepts is 20% of the Cisco CyberOps Associate 200-201 exam. It covers the CIA triad, threat actors and malware, attack types and vectors, social engineering, cryptographic fundamentals, and compliance frameworks such as PCI DSS, GDPR, HIPAA, and SOX. Questions are scenario-based: identify an attack, map traffic to a technique, or select the governing regulation.

143 questions32 easy77 medium34 hard

Focused practice

Practice Security Concepts questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Security Concepts

You must read a scenario and classify the attack, control, or regulation it describes, then justify the choice. The single most important skill is matching the specific detail in the question, such as cardholder data or EU citizens' data, to the correct framework or technique.

Classifying attacks like DDoS, reconnaissance, and social engineering from scenario descriptions

Mapping compliance frameworks (PCI DSS, GDPR, HIPAA) to stated data-protection requirements

Applying the CIA triad and identifying confidentiality, integrity, or availability impacts

Recognizing malware types, threat actor motivations, and cryptographic concepts like hashing and PKI

Watch out for

Common Security Concepts exam traps

  • ▸Confusing active reconnaissance (scanning, probing) with passive reconnaissance (traffic monitoring), which changes which traffic a firewall should block
  • ▸Mixing up compliance frameworks, such as choosing HIPAA instead of PCI DSS for cardholder data or GDPR for EU personal data
  • ▸Treating a DDoS attack as a single-source intrusion when the scenario describes many compromised systems flooding one target

Question index

All Security Concepts questions (143)

Click any question to see the full explanation, or start a practice session above.

1

An organization wants to ensure that a received email genuinely came from the claimed sender and has not been altered. Which cryptographic mechanism provides both authentication and integrity?

Hard
2

A healthcare organization must comply with HIPAA. Which THREE security measures are typically required under HIPAA? (Choose three.)

Medium
3

An organization wants to ensure that data sent over the internet cannot be read if intercepted. Which cryptographic method should be used?

Hard
4

A security analyst is reviewing a recent security incident where an attacker gained unauthorized access to a server. The analyst needs to determine which factors contributed to the incident by examining the vulnerability, threat, and risk. Which TWO of the following best describe the relationship between these concepts in this scenario? (Choose two.)

Hard
5

A security analyst observes repeated failed login attempts from a single external IP address, causing the authentication server to become unresponsive. Which type of attack is occurring?

Medium
6

An attacker uses a tool to capture keystrokes on a compromised system. What type of malware is most likely in use?

Medium
7

A security analyst is reviewing logs and notices that an attacker has intercepted and modified communications between two devices on the same network. Which attack technique is being used?

Medium
8

A security analyst is selecting a symmetric encryption algorithm for encrypting data at rest. Which of the following is a suitable symmetric algorithm?

Hard
9

What is the primary difference between symmetric and asymmetric encryption?

Medium
10

A security analyst is reviewing a suspicious email reported by a user. The email appears to come from the CEO and requests an urgent wire transfer. The analyst examines the email headers and notices that the 'From' address is spoofed and the 'Reply-To' address is different from the 'From' address. The email also contains a link to a credential-harvesting page. Which type of attack is this?

Hard
11

A security analyst is examining a suspicious executable found on a user's workstation. The file appears to be a legitimate PDF document but when opened, it executes code that encrypts the user's files and demands payment. The analyst determines that the file is actually a malicious program disguised as a benign file. Which type of malware is this?

Easy
12

A security analyst is investigating a potential data exfiltration incident. The analyst observes that a large amount of data is being transferred from an internal database server to an external IP address during non-business hours. The transfer is using an encrypted channel that is not typical for the server's normal operations. Which type of threat is this activity most likely associated with?

Medium
13

Which cryptographic method uses the same key for both encryption and decryption, and is typically faster than asymmetric encryption?

Medium
14

Which TWO of the following are examples of malware that rely on user interaction to spread? (Select two.)

Easy
15

An analyst is examining a suspicious executable recovered from a compromised host. Static analysis shows it is packed, and dynamic analysis in a sandbox reveals it creates a mutex, modifies registry Run keys, and attempts to connect to a hardcoded IP address on port 443. The file also contains a section with high entropy. Which characteristic most strongly suggests the file is packed or encrypted?

Medium
16

A security analyst is notified that an employee's laptop was stolen. The laptop contains sensitive customer data. Which type of threat does this incident represent?

Easy
17

An organization is reviewing its exposure to attack surface. A security architect notes that employees routinely install browser extensions from unapproved sources, and several internal web applications accept unsanitized input. Which concept do these findings primarily describe?

Medium
18

A security analyst is evaluating the risk of a new vulnerability in a web application. The vulnerability has a CVSS base score of 9.8 and is remotely exploitable without authentication. The application is internet-facing and processes sensitive customer data. Which risk response strategy is MOST appropriate according to risk management principles?

Hard
19

During a security audit, it is discovered that an organization’s network is vulnerable to ARP spoofing attacks. Which type of attack could result from exploiting this vulnerability?

Hard
20

A security analyst is classifying security controls for a new data center. Which TWO of the following are examples of physical controls? (Choose two.)

Medium
21

A security engineer is implementing controls to meet compliance requirements. Which TWO of the following frameworks are specifically designed for protecting personal data?

Medium
22

A security analyst at a mid-sized company is reviewing a packet capture from the DMZ and notices a series of TCP SYN packets sent to multiple ports on a single internal web server, all originating from the same external IP address within a 3-second window. None of the SYN packets are followed by a completed three-way handshake. The analyst must classify this activity to determine the appropriate response. Which type of attack is most consistent with this traffic pattern?

Medium
23

A security team is implementing a defense-in-depth strategy and wants to ensure that even if an attacker compromises a web server, the attacker cannot easily move laterally to the internal database server. Which security principle is being applied when the team segments the network and restricts traffic between the web tier and the database tier?

Easy
24

Which of the following best describes a vulnerability?

Easy
25

An organization experiences a ransomware attack where files are encrypted and a ransom is demanded. Which element of the CIA triad is most directly impacted?

Medium
26

An organization wants to implement a security framework that includes functions such as Identify, Protect, Detect, Respond, and Recover. Which framework aligns with this structure?

Hard
27

During a penetration test, a security engineer uses publicly available information from LinkedIn and Google to gather details about employees and organizational structure. Which type of reconnaissance is being performed?

Hard
28

A security analyst is reviewing the organization's defense-in-depth strategy. The analyst must recommend TWO controls that specifically reduce the risk of successful phishing attacks against employees. Which two controls should the analyst recommend? (Choose two.)

Medium
29

A security analyst is investigating a recent security incident and needs to determine the extent of the compromise. The analyst wants to understand which systems were affected and what data may have been accessed. Which phase of the incident response process is the analyst currently performing?

Medium
30

A security analyst is assessing the risk profile of a new cloud-based collaboration application that employees want to adopt. The analyst must identify which factors contribute to the overall risk of introducing this application into the environment. (Choose two.)

Medium
31

A security engineer discovers that an attacker has inserted fake entries into a DNS resolver's cache, redirecting users to a malicious website. Which attack has occurred?

Medium
32

What is the primary purpose of a digital certificate in a Public Key Infrastructure (PKI)?

Medium
33

Which element of the CIA triad ensures that data cannot be modified by unauthorized parties?

Easy
34

A company needs to comply with regulations that protect personal data of EU citizens. Which TWO compliance frameworks are directly relevant to this requirement? (Choose two.)

Easy
35

A security analyst is reviewing the organization's incident response plan. The plan currently defines containment, eradication, and recovery but does not include a formal step to determine the root cause of an incident. Which phase of the NIST SP 800-61 incident response lifecycle should the analyst add to address this gap?

Medium
36

A security analyst is assessing the risks to a company's data. The analyst identifies a vulnerability in the web application that could allow SQL injection. Which TWO terms correctly describe the elements of this risk scenario? (Choose two.)

Easy
37

An attacker uses a tool to scan all IP addresses in a range to identify which hosts are online and what services are running. Which type of reconnaissance is this?

Medium
38

Which compliance framework specifically addresses the protection of cardholder data?

Medium
39

A security analyst is examining a network capture and observes that an attacker is sending a large volume of SYN packets to a web server with spoofed source IP addresses. The server's connection table is filling up, and legitimate users cannot connect. Which type of attack is the analyst observing?

Medium
40

A security analyst is investigating a breach where an attacker gained access to a server by exploiting a vulnerability in a web application. The analyst needs to determine the type of attack that was used. The server logs show that the attacker sent a specially crafted HTTP request that caused the server to execute arbitrary code. Which type of attack is this?

Hard
41

A security analyst is examining a memory dump from a compromised host and finds a small piece of code that resides only in memory, has no corresponding file on disk, and injects itself into a running legitimate process. The code does not replicate to other systems. Which type of malware best describes this?

Hard
42

A company is implementing a security policy to reduce risk. Which THREE activities are examples of risk mitigation? (Choose three.)

Hard
43

Which THREE components are part of a Public Key Infrastructure (PKI)? (Choose three.)

Hard
44

Which term describes a weakness in a system that could be exploited by a threat?

Easy
45

A security administrator needs to verify that a downloaded file has not been altered during transit. Which cryptographic technique should be used?

Easy
46

A security operations center (SOC) analyst is investigating a security incident where an attacker gained initial access to a corporate network. The analyst suspects the attacker used a technique that involves exploiting a vulnerability in a public-facing web server to execute arbitrary code. Which phase of the Cyber Kill Chain does this activity represent?

Hard
47

Which type of malware is designed to encrypt files on a victim's system and demand payment for the decryption key?

Medium
48

A security analyst is evaluating an endpoint detection and response deployment for a company that must detect fileless attacks. Which TWO techniques should the analyst expect the tool to monitor because they are commonly used by fileless malware? (Choose two.)

Medium
49

A security analyst discovers that an employee's computer is infected with malware that encrypts files and demands payment. What type of malware is this?

Easy
50

Which of the following best describes the relationship between a vulnerability, threat, and risk in cybersecurity?

Easy
51

A security analyst is investigating an alert about a workstation that is repeatedly resolving domain names for known malicious command-and-control servers. The analyst wants to determine whether the workstation is infected with malware that uses DNS for communication. Which type of malware behavior is most likely occurring?

Easy
52

A security analyst at a retail company is reviewing DNS logs and notices a workstation repeatedly resolving random-looking subdomains such as a8f3k2.example-bad.com, followed by a long TXT record response containing encoded data. No user reported visiting any website. Which technique is most likely occurring?

Medium
53

A security analyst is evaluating the organization's use of cryptographic algorithms. The analyst must identify which TWO algorithms are symmetric encryption algorithms that can be used for bulk data encryption. (Choose two.)

Medium
54

A security analyst is examining a suspicious executable found on a compromised host. The analyst runs the file in a sandbox and observes that it creates a mutex named 'Global\MyMutex123', attempts to connect to an external IP address on port 443, and modifies the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Run. Which type of analysis is the analyst performing?

Hard
55

A security analyst is reviewing a packet capture and notices that an attacker is sending a large number of SYN packets to a web server from spoofed source IP addresses. The server's connection table is filling up, and legitimate users cannot connect. Which type of attack is being described?

Hard
56

A security analyst needs to ensure that a message has not been tampered with during transit and that the sender cannot deny sending it. Which cryptographic method should be used?

Hard
57

A security analyst is investigating a potential data breach. Which two actions are examples of passive reconnaissance? (Choose two.)

Medium
58

A company's web server is overwhelmed by traffic from multiple compromised systems, causing it to become unresponsive to legitimate users. Which type of attack is this?

Medium
59

A security team is reviewing the confidentiality, integrity, and availability (CIA) triad for a new file-sharing service. The service must ensure that data cannot be altered in transit by unauthorized parties. Which security principle is primarily addressed by implementing TLS for all connections?

Easy
60

A security team is analyzing a malware infection. Which two characteristics are typical of a worm? (Choose two.)

Medium
61

A security analyst needs to verify the authenticity and integrity of a software update. The update is signed with a digital signature. Which key is used to verify the signature?

Medium
62

A security analyst is reviewing a packet capture and notices that a host is sending TCP segments with the SYN flag set to a range of ports on a single target, but the source IP address in each segment is spoofed to a different random address. The target replies with SYN-ACK packets to those spoofed addresses, and the host never completes the handshake. Which type of attack is this host performing?

Medium
63

A security analyst is reviewing a packet capture of traffic entering the corporate network. The analyst notices a large number of TCP SYN packets sent to multiple destination ports on a single internal host, with no corresponding ACK packets. The source IP addresses are spoofed and vary across each packet. Which type of attack is this traffic MOST likely associated with?

Medium
64

A security analyst is reviewing a suspicious file found on a user's workstation. The file has a .docx extension but when the analyst inspects its header bytes, the file begins with the magic number for a Windows Portable Executable. The user reports the file arrived as an email attachment. Which type of malware delivery technique does this describe?

Easy
65

Which encryption method uses a single key for both encryption and decryption of data?

Medium
66

A security analyst is reviewing logs from a web server and notices a high volume of HTTP requests from a single IP address targeting the same login page within a short time frame. The analyst suspects a brute force attack. Which TWO actions are most appropriate to mitigate this type of attack? (Choose two.)

Medium
67

Which type of malware is designed to replicate itself and spread to other systems without user intervention?

Medium
68

A security analyst at a mid-sized company is reviewing the organization's risk management strategy. The CIO asks the analyst to describe the primary purpose of a vulnerability assessment. Which statement best describes this purpose?

Easy
69

A security analyst discovers that an attacker is using a vulnerability scanning tool to identify open ports on the company's network. Which type of attack is being performed?

Easy
70

Which NIST Cybersecurity Framework function involves developing and implementing appropriate safeguards to ensure delivery of critical infrastructure services?

Easy
71

An attacker intercepts communication between a client and server and modifies the data being transmitted. The client and server are unaware of the modification. Which type of attack is being performed?

Hard
72

A security analyst is reviewing the access control strategy for a research and development department. The department handles highly sensitive intellectual property, and the organization wants to ensure that employees can only access information strictly necessary for their current project tasks, even if they have previously worked on other projects. Which access control principle is being enforced?

Medium
73

A security analyst is reviewing a packet capture and observes that a workstation is sending a large volume of TCP SYN packets to many different destination IP addresses on port 445, with no corresponding completed handshakes. The analyst suspects malware is performing reconnaissance. Which type of activity is this workstation most likely performing?

Medium
74

Which element of the CIA triad is primarily compromised when an attacker successfully intercepts and reads encrypted network traffic without authorization?

Easy
75

A security analyst is reviewing network traffic and observes a large number of DNS queries for randomly generated domain names, such as 'a1b2c3d4e5f6g7h8.com', from a single internal host. The queries are followed by responses with very short TTL values. The analyst suspects the host is compromised. Which type of malicious activity is most likely occurring?

Medium
76

Which cryptographic technique uses a public and private key pair to provide non-repudiation?

Medium
77

An attacker intercepts communication between two parties and modifies the data before forwarding it. Which type of attack is this?

Medium
78

A company's web server is overwhelmed with traffic from many compromised devices, causing legitimate users to be unable to access the site. What type of attack is this?

Medium
79

A user receives an email that appears to be from their bank, asking them to click a link and verify their account details. The email contains a sense of urgency. Which type of attack is this?

Medium
80

A security analyst is examining a suspicious executable found on a compromised host. Static analysis reveals that the file contains a packer and obfuscated strings. When run in a sandbox, it attempts to connect to an external IP address and modifies registry keys for persistence. Which stage of the cyber kill chain does the registry modification represent?

Medium
81

A security administrator is reviewing the company's incident response plan and wants to ensure that the team understands the difference between a vulnerability, a threat, and a risk. During a tabletop exercise, the administrator presents a scenario: a web server has an unpatched Apache Struts vulnerability, and a known exploit exists publicly. Which term best describes the unpatched Apache Struts vulnerability in this context?

Easy
82

An analyst is investigating a malware infection on a workstation. The malware appears to be a trojan that downloads additional payloads and allows remote control. The analyst needs to classify the malware based on its behavior. Which THREE characteristics match this description? (Choose three.)

Hard
83

A security analyst is reviewing logs and notices that an attacker has intercepted and modified communications between two devices without their knowledge. Which type of attack is this?

Medium
84

A company processes credit card payments and must comply with a framework that mandates specific security controls for protecting cardholder data. Which compliance framework applies?

Hard
85

Which compliance framework is specifically designed to protect the privacy and security of electronic health information in the United States?

Medium
86

A company wants to protect its web application from injection attacks by ensuring that user-supplied input is not interpreted as code by the backend database. Which control should be implemented?

Medium
87

Which type of malware is characterized by self-replication and spreading to other systems without user interaction, often causing network congestion?

Medium
88

A security analyst is configuring a firewall to block common reconnaissance techniques. Which THREE types of reconnaissance traffic should be blocked to prevent active reconnaissance? (Choose three.)

Medium
89

A security analyst is reviewing a suspicious file recovered from a compromised endpoint. The file contains a macro that, when opened, launches PowerShell to download a second-stage payload from a remote server. The analyst wants to classify this file based on its behavior. Which classification is most accurate?

Hard
90

A security analyst is investigating a potential data breach. The analyst identifies that the attacker used a technique to impersonate a legitimate user by spoofing the MAC address and IP address. Which TWO types of network attacks could involve these techniques? (Choose two.)

Medium
91

A security analyst is evaluating risks and calculates that a threat has a likelihood of 0.5 and an impact of $200,000. What is the risk value?

Hard
92

A security analyst is investigating a recent security breach. The analyst discovers that an attacker gained access to the network by exploiting a vulnerability in an unpatched web server. After gaining access, the attacker moved laterally to other systems and exfiltrated sensitive data. The organization wants to improve its security posture to prevent similar incidents. Which security concept best describes the attacker's actions after initial compromise?

Medium
93

A security analyst is investigating an incident where an attacker gained initial access to a corporate network. The analyst finds that the attacker sent a phishing email with a link to a malicious website that exploited a vulnerability in the user's browser. Which phase of the Cyber Kill Chain does the browser exploitation represent?

Medium
94

Which security concept describes the potential for a threat to exploit a vulnerability, and is often expressed as a combination of likelihood and impact?

Easy
95

A security analyst is reviewing a packet capture from the DMZ and sees a host at 203.0.113.45 sending a flood of TCP segments with the SYN flag set to many different destination ports on a single internal web server, all within a few seconds. The source IP never completes the three-way handshake. Which type of attack is this host most likely performing?

Medium
96

During an incident, an analyst finds a workstation that is beaconing to an external IP every 60 seconds using DNS TXT queries. The queries contain long, base64-encoded subdomains. The endpoint has no other suspicious network connections. Which technique is most likely being used?

Hard
97

An organization needs to ensure that a document has not been altered and to verify the sender's identity. Which combination of cryptographic techniques should be used?

Hard
98

A company wants to ensure that only authorized employees can enter the server room. Which type of control is a badge reader at the door?

Easy
99

A security analyst is reviewing a vulnerability scan report and sees a finding labeled 'CVE-2021-44228' with a CVSS score of 10.0. The analyst needs to prioritize remediation. Which factor does the CVSS score primarily represent?

Medium
100

During a security assessment, an analyst uses the Shodan search engine to find exposed industrial control systems. Which phase of the attack lifecycle does this activity represent?

Hard
101

A security analyst is reviewing the cryptographic mechanisms used to protect data in transit and at rest. The organization wants to ensure confidentiality and integrity for sensitive files stored on a server and for data sent over a VPN. Which TWO of the following mechanisms provide both confidentiality and integrity for data? (Choose two.)

Medium
102

An analyst is reviewing network traffic and observes a series of DNS queries for long, random-looking subdomains of a single domain, followed by large TXT record responses. The queries occur at regular intervals and the volume is unusually high. Which type of attack is most likely indicated?

Hard
103

An attacker sends an email that appears to come from the company's IT department, asking the recipient to click a link and reset their password due to a security breach. Which type of social engineering is this?

Medium
104

A security analyst is evaluating the risk of a new web application that will store customer credit card data. The analyst needs to determine the likelihood and impact of a data breach. Which risk analysis approach involves assigning numerical values to assets, threats, and vulnerabilities to calculate an annualized loss expectancy (ALE)?

Medium
105

Which element of the CIA triad is primarily concerned with preventing unauthorized access to data?

Easy
106

An organization is implementing a new security control that will verify the integrity of critical system files by comparing their current hash values against known good baseline values. Which security concept does this control primarily address?

Easy
107

A security analyst is reviewing the organization's incident response plan and wants to ensure it aligns with the NIST incident response lifecycle. Which two phases are part of the NIST incident response lifecycle? (Choose two.)

Medium
108

Which phase of the NIST Cybersecurity Framework involves actions to limit the impact of a cybersecurity incident?

Easy
109

A security team is designing a defense-in-depth strategy. They want to add a control that inspects the actual content of network traffic for known attack signatures and can block or alert on malicious payloads in real time. Which technology best meets this requirement?

Easy
110

An organization wants to ensure the integrity of software updates downloaded from its vendor's website. The vendor provides a hash value for each update. Which TWO properties of hashing algorithms make them suitable for integrity verification? (Choose two.)

Medium
111

A security analyst is examining a log file and notices that the hash value of a configuration file does not match the expected value. Which security goal has been violated?

Medium
112

A security analyst is identifying potential vulnerabilities in the network. Which TWO of the following are examples of passive reconnaissance?

Easy
113

A security analyst discovers that a server's configuration allows users to access files outside of their intended directory. In security terminology, what is this weakness called?

Medium
114

A hospital's security team discovers that a network device is silently forwarding copies of all traffic to an internal host that no administrator recognizes. The device is a managed switch that connects the radiology VLAN to the core. Which attack has most likely been implemented against this switch?

Medium
115

Which of the following is an example of a symmetric encryption algorithm?

Medium
116

A financial services firm is building a threat model and wants to classify an attacker who is highly skilled, well funded, and focused on stealing intellectual property from a specific set of companies over a long period. Which threat actor category best fits this profile?

Hard
117

An organization wants to ensure that a user cannot deny having sent an email. Which security goal does this address?

Hard
118

A company's security policy requires that sensitive data be encrypted at rest using AES-256. Which type of encryption does AES-256 represent?

Medium
119

A security analyst discovers that a malicious actor is using a technique to gather information about employees by searching social media sites. Which type of attack is being performed?

Easy
120

An attacker intercepts communication between a client and a server, allowing the attacker to read, insert, and modify messages in both directions. Which type of network attack is this?

Hard
121

A security analyst is investigating an incident where an employee received an email that appeared to be from the company's IT department, requesting the employee to verify their account by clicking a link and entering their credentials. The employee complied, and later the attacker used those credentials to access the corporate VPN. Which combination of attack types best describes this incident?

Hard
122

A security operations center is building detection rules for man-in-the-middle attacks on its internal network. The team wants to identify techniques an attacker on the same Layer 2 segment could use to intercept or redirect traffic between two hosts. (Choose two.)

Medium
123

A security analyst discovers that an attacker used a publicly available tool to scan a company's network for open ports and services. What type of attack is this?

Easy
124

A security analyst is reviewing an incident in which an attacker gained initial access to a corporate workstation by exploiting a vulnerability in a browser plugin. After gaining access, the attacker moved laterally to a file server and exfiltrated data. The analyst must map these activities to the cyber kill chain. Which phase of the kill chain does the browser plugin exploitation represent?

Hard
125

A security analyst is evaluating the security posture of a new web application. The analyst needs to identify which TWO of the following are examples of security controls that fall under the category of technical controls. (Choose two.)

Medium
126

An organization implements encryption for all sensitive data at rest and in transit to prevent unauthorized access. Which element of the CIA triad is being primarily addressed?

Easy
127

A network analyst notices a high volume of traffic from a single external IP address to multiple internal hosts on port 443. The traffic includes incomplete TCP handshakes. Which type of reconnaissance is being performed?

Medium
128

A security analyst is reviewing the risk associated with a new cloud service. The service provider stores data in multiple countries, and the data includes personal information of EU citizens. The analyst must ensure compliance with GDPR. Which principle of GDPR is most directly relevant to this scenario?

Medium
129

An attacker sends an email posing as the company's IT department, asking employees to click a link and enter their credentials. Which type of social engineering attack is this?

Medium
130

Which component of the NIST Cybersecurity Framework involves taking action to stop an ongoing attack?

Easy
131

An organization must comply with a regulation that requires protecting the privacy of EU citizens' personal data. Which compliance framework applies?

Hard
132

In a PKI, what is the role of a Certificate Authority (CA)?

Hard
133

An analyst is investigating an incident and needs to determine the source of a piece of malware. The analyst finds that the malware uses a domain generation algorithm to contact command-and-control servers. Which term best describes this capability?

Medium
134

Which THREE of the following are common types of malware?

Medium
135

A security analyst needs to verify that a downloaded software update has not been tampered with. The update's publisher provides a file containing a hash value. Which process should the analyst use to verify integrity?

Hard
136

A security analyst at a financial services company is reviewing the organization's security program. The CISO wants to ensure that the confidentiality, integrity, and availability of information assets are protected by administrative, physical, and technical controls. Which security concept is the CISO describing?

Easy
137

A security analyst is investigating a network breach. Which TWO activities are examples of passive reconnaissance? (Choose two.)

Medium
138

An organization is required to protect cardholder data. Which compliance framework applies to this requirement?

Medium
139

A security operations center analyst is reviewing a vulnerability scan report for a web server. The report identifies that the server is running an outdated version of Apache HTTP Server with a known remote code execution vulnerability. The analyst needs to classify this finding. Which term best describes this vulnerability?

Medium
140

An organization wants to protect sensitive data at rest and in transit. Which THREE cryptographic methods can provide confidentiality? (Choose three.)

Medium
141

An attacker sends a fraudulent email that appears to come from the company's IT department, requesting that the recipient click a link and enter their login credentials. Which type of social engineering attack is this?

Medium
142

Which compliance standard specifically applies to organizations that handle credit card information?

Medium
143

A security engineer is analyzing a recent data breach. Which TWO are examples of active reconnaissance techniques? (Select two.)

Medium

Frequently asked questions

What does the Security Concepts domain cover on the 200-201 exam?
You must read a scenario and classify the attack, control, or regulation it describes, then justify the choice. The single most important skill is matching the specific detail in the question, such as cardholder data or EU citizens' data, to the correct framework or technique.
How many questions are in this domain?
This page lists all 143 Security Concepts questions in the 200-201 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Security Concepts questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
cisco-cyberops-associate CISCO-CYBEROPS-ASSOCIATE cbrops security concepts Practice Questions