Sample questions
Cisco CyberOps Associate 200-201 practice questions
A security analyst is triaging an alert about a user downloading a suspicious file. According to the NIST SP 800-61 Rev 2 incident response process, in which phase does initial tri…
A network intrusion detection system (NIDS) generates an alert for a known exploit against a web server. The analyst verifies that the server is patched. What is the next best step…
An analyst is investigating a Windows host and observes a suspicious process with PID 1337. Which THREE of the following Volatility commands would provide useful information about…
An analyst is investigating a Windows host that likely has malware persistence via the registry. Which TWO registry hives are commonly used to store Run keys for user logon persist…
An organization's security policy mandates that all external media (USB drives, external hard drives) must be scanned for malware before use. An employee inserts a USB drive to tra…
A security analyst is investigating a potential brute force attack. Which SIEM correlation rule would best detect this activity?
Which type of malware is designed to spread automatically across networks without user interaction?
During the containment phase of an incident, the IR team decides to power off a compromised server to prevent further damage. However, they later realize that this action may have…
Which tool can be used to extract files from a PCAP file for further analysis?
In a Linux system, an analyst wants to check for unauthorized cron jobs. Which of the following is a common location for user-specific cron jobs?
In a PCAP, an analyst sees a large outbound data transfer over FTP to an external IP address during non-business hours. The source host is a database server. Which phase of the Cyb…
A network analyst finds a PCAP with a series of DNS queries for subdomains like "data12345.example.com" and "data67890.example.com" where the subdomain names appear to contain enco…
Which THREE are typical sources of log data used in security monitoring? (Choose three.)
A security analyst detects a host infected with ransomware on the corporate network. According to incident response procedures, what should be the first action?
An analyst detects traffic from an internal host that periodically sends small DNS queries to a domain with high entropy subdomains (e.g., 'a3k9f2.example.com'). The domain is not…
Which compliance framework specifically addresses the protection of cardholder data?
A network analyst is examining a PCAP and sees a large number of ICMP echo request packets sent from a single internal host to multiple external IP addresses, with varying payload…
Drag and drop the steps to configure a Cisco ASA firewall for basic network access into the correct order.
Refer to the exhibit. An analyst sees this syslog message from a Cisco ASA. What does this log entry indicate?
An organization is developing an Acceptable Use Policy (AUP). Which of the following topics is typically covered in an AUP?
Which type of traffic is most prominent in this NetFlow data?
A security analyst observes a large number of SYN packets sent to various ports on a target host, receiving RST responses for closed ports and no response for open ports. Which pha…
A SOC analyst needs to create a SIEM correlation rule to detect a brute force attack against SSH on a server. Which of the following would be the most effective rule logic?
In the Cyber Kill Chain model, which phase involves delivering the exploit to the target, such as via email attachment or malicious link?