Courseiva
Back to Cisco CyberOps Associate 200-201 questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise Cisco CyberOps Associate 200-201 practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
200-201
exam code
Cisco
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related 200-201 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1mediummulti select
Full question →

A security analyst is analyzing system logs and notices multiple failed authentication events followed by a successful login from the same user account, and then a privilege escalation event. Which THREE events should be correlated to detect a potential attack?

Question 2hardmulti select
Full question →

An analyst is investigating a Windows host and observes a suspicious process with PID 1337. Which THREE of the following Volatility commands would provide useful information about this process? (Choose three.)

Question 3mediummulti select
Full question →

A security analyst is investigating a PCAP that shows multiple failed SMB authentication attempts from a single host to different IP addresses, followed by a successful authentication. Which TWO techniques are likely being used?

Question 4hardmulti select
Read the full DNS explanation →

A security analyst discovers that an attacker exfiltrated data using DNS tunneling. Which TWO controls should be implemented to detect or prevent this? (Select two.)

Question 5easymulti select
Full question →

Which TWO of the following are key components of a security policy? (Choose two.)

Question 6hardmulti select
Full question →

Which TWO characteristics are typical of host-based intrusion detection systems (HIDS) compared to network-based intrusion detection systems (NIDS)?

Question 7mediummulti select
Full question →

An organization wants to protect sensitive data at rest and in transit. Which THREE cryptographic methods can provide confidentiality? (Choose three.)

Question 8hardmulti select
Full question →

Which THREE are typical sources of log data used in security monitoring? (Choose three.)

Question 9easymulti select
Full question →

Which two Sysmon Event IDs are most commonly associated with code injection techniques?

Question 10hardmulti select
Read the full DNS explanation →

An analyst is investigating a potential data exfiltration. Which two indicators in network traffic are most indicative of data exfiltration over DNS? (Choose two.)

Question 11easymulti select
Full question →

A security analyst is creating a network baseline for normal traffic patterns. Which TWO metrics should be included to detect anomalies?

Question 12hardmulti select
Read the full DNS explanation →

An analyst suspects a host is communicating with a command-and-control server using DNS tunneling. Which THREE network traffic patterns would support this hypothesis?

Question 13hardmulti select
Full question →

Which THREE factors should be considered when tuning an IPS signature? (Choose three.)

Question 14hardmulti select
Full question →

Which THREE of the following are indicators that a network may be compromised by a botnet?

Question 15mediummulti select
Full question →

Which TWO of the following are typically included in a security policy's scope statement?

Question 16mediummulti select
Full question →

Which TWO of the following are best practices when configuring a SIEM for security monitoring?

Question 17easymulti select
Full question →

A security analyst is investigating a host that is suspected of being compromised. The analyst runs a series of commands to gather information. Which TWO of the following commands are most useful for collecting volatile data from a live Windows system? (Choose two.)

Question 18mediummulti select
Full question →

Which THREE of the following are key elements of a security monitoring and analysis strategy? (Choose three.)

Question 19mediummulti select
Full question →

A security analyst is examining system logs for signs of privilege escalation. Which THREE events are most relevant to detect such activity?

Question 20hardmulti select
Full question →

A SOC analyst is reviewing a large number of alerts from a SIEM. Which THREE of the following are effective steps to prioritize and investigate alerts in a high-volume environment? (Choose three.)

These 200-201 practice questions are part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style 200-201 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.