Courseiva
← Back to Cisco CyberOps Associate 200-201 questions

Scenario-based practice

Refer to the Exhibit Practice Questions

Practise Cisco CyberOps Associate 200-201 practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

15
scenario questions
200-201
exam code
Cisco
vendor

Scenario guide

How to approach refer to the exhibit practice questions

Practise exhibit-style questions that ask you to read a topology, table, command output or diagram before choosing the best answer.

Quick answer

Exhibit-style questions test whether you can read a topology, command output, diagram or table before choosing the best answer.

How to extract the relevant detail from an exhibit.

How topology, command output or routing information affects the answer.

How to avoid answering from memory before reading the evidence.

How to map the exhibit back to the exam objective.

Related practice questions

Related 200-201 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Refer to the exhibit. An analyst sees this syslog message from a Cisco ASA. What does this log entry indicate?

Exhibit

Refer to the exhibit.
```
Mar  1 12:34:56 192.168.1.100 %ASA-4-106023: Deny tcp src outside:10.0.0.1/54321 dst inside:192.168.1.100/80 by access-group "OUTSIDE_IN" [0x0, 0x0]
```
Question 2easymultiple choice
Full question →

Refer to the exhibit. Which security protocol is being configured?

Exhibit

crypto isakmp policy 10
 encr aes 256
 authentication pre-share
 group 5
Question 3easymultiple choice
Full question →

Refer to the exhibit. What type of activity does this log represent?

Exhibit

Sep 10 12:34:56: %SEC-6-IPACCESSLOGP: list 100 denied tcp 10.0.0.1(1234) -> 192.168.1.1(22), 1 packet
Sep 10 12:34:57: %SEC-6-IPACCESSLOGP: list 100 denied tcp 10.0.0.1(1235) -> 192.168.1.1(22), 1 packet
Sep 10 12:34:58: %SEC-6-IPACCESSLOGP: list 100 denied tcp 10.0.0.1(1236) -> 192.168.1.1(22), 1 packet
Question 4hardmultiple choice
Full question →

Refer to the exhibit. Based on the intrusion event, what is the likely intent of the traffic?

Exhibit

Event: 1
Timestamp: 2023-04-10 14:23:45
Source IP: 10.0.1.5
Destination IP: 192.168.1.100
Signature: "SHELLCODE x86 NOOP Unspecified"
Classification: Attempted Administrator Privilege Gain
Priority: 1
Action: Alert
Question 5hardmultiple choice
Review the full routing breakdown →

Refer to the exhibit. A network administrator notices that remote SSH logins to the router succeed, but the router is not sending accounting records. Based on the configuration, what is the most likely cause?

Exhibit

Refer to the exhibit.

! Output from show running-config | include aaa
! on a Cisco router
aaa new-model
aaa authentication login default local
aaa authentication login CONSOLE none
aaa authorization exec default local
aaa accounting exec default start-stop group tacacs+
! 
! Output from show running-config | include tacacs
! on the same router
tacacs server TACACS1
 address ipv4 192.168.1.100
 key cisco123
!
Question 6mediummultiple choice
Full question →

Refer to the exhibit. A network analyst sees these firewall logs. What is the most likely interpretation?

Exhibit

Refer to the exhibit.
```
Mar  1 12:34:56.789: %ASA-5-111008: User 'admin' executed the 'configure terminal' command.
Mar  1 12:35:01.123: %ASA-4-106023: Deny tcp src outside:192.0.2.10/12345 dst inside:10.0.0.1/80 by access-group "OUTSIDE_IN" [0x0, 0x0]
Mar  1 12:35:05.456: %ASA-4-106023: Deny tcp src outside:192.0.2.10/12346 dst inside:10.0.0.2/443 by access-group "OUTSIDE_IN" [0x0, 0x0]
```
Question 7mediummultiple choice
Full question →

Refer to the exhibit. A host-based analyst reviews auth.log. What does the accepted password log entry indicate?

Exhibit

Refer to the exhibit.

```
Aug 10 14:32:17 host1 sshd[2345]: Failed password for root from 192.168.1.100 port 34567 ssh2
Aug 10 14:32:20 host1 sshd[2345]: Failed password for root from 192.168.1.100 port 34568 ssh2
Aug 10 14:32:23 host1 sshd[2345]: Failed password for root from 192.168.1.100 port 34569 ssh2
Aug 10 14:32:26 host1 sshd[2346]: Accepted password for admin from 192.168.1.100 port 34570 ssh2
```
Question 8hardmultiple choice
Full question →

Refer to the exhibit. An analyst sees repeated denied TCP connections from the same source to the same destination web server. Which of the following actions should the analyst take first?

Exhibit

%ASA-4-106023: Deny tcp src outside:10.0.0.1/12345 dst inside:192.168.1.10/80 by access-group "outside" [0x0, 0x0]
%ASA-4-106023: Deny tcp src outside:10.0.0.1/12346 dst inside:192.168.1.10/80 by access-group "outside" [0x0, 0x0]
%ASA-4-106023: Deny tcp src outside:10.0.0.1/12347 dst inside:192.168.1.10/80 by access-group "outside" [0x0, 0x0]
Question 9hardmultiple choice
Full question →

Refer to the exhibit. A security analyst is reviewing the ASA configuration. Which traffic will be permitted from the outside interface?

Exhibit

access-list OUT extended permit tcp any host 10.1.1.1 eq 80
access-list OUT extended deny ip any any
access-group OUT in interface outside
Question 10easymultiple choice
Full question →

Refer to the exhibit. An EDR alert shows this JSON event. What is the most significant indicator of a potential malware infection?

Exhibit

Refer to the exhibit.
```
{
  "event": "Process Creation",
  "timestamp": "2024-08-01T10:00:00Z",
  "hostname": "DESKTOP-ABC123",
  "user": "jsmith",
  "process": "C:\\Users\\jsmith\\Downloads\\invoice.exe",
  "parent_process": "C:\\Windows\\explorer.exe"
}
```
Question 11mediummultiple choice
Read the full network assurance explanation →

An analyst reviews the Cisco ASA syslog message shown in the exhibit. What does this entry indicate?

Exhibit

Refer to the exhibit.
%ASA-4-106023: Deny tcp src outside:203.0.113.45/56789 dst inside:10.1.1.100/80 by access-group "outside_in"
Question 12hardmultiple choice
Full question →

Based on the exhibit, what does the sequence of events indicate?

Exhibit

Refer to the exhibit.

Event 4688 (Process Creation):
New Process ID: 0x1234
New Process Name: C:\Users\Public\svchost.exe
Creator Process ID: 0x9ABC
Creator Process Name: C:\Windows\System32\wmiprvse.exe
Process Command Line: svchost.exe -k ntsvcs

Event 4688 (Process Creation):
New Process ID: 0x5678
New Process Name: C:\Windows\System32\svchost.exe
Creator Process ID: 0x1234
Creator Process Name: C:\Users\Public\svchost.exe
Process Command Line: C:\Windows\System32\calc.exe
Question 13hardmulti select
Full question →

A security analyst is reviewing the firewall log exhibit. The analyst suspects that this traffic might be part of a command-and-control (C2) communication based on the packet size and the timing of similar events. Which TWO additional pieces of evidence would most strongly support the suspicion of C2 traffic?

Exhibit

Refer to the exhibit.

```
Event: Firewall log entry
Time: 2023-10-05 14:23:45
Source IP: 192.168.1.50
Destination IP: 203.0.113.5
Source Port: 49152
Destination Port: 443
Protocol: TCP
Action: ALLOW
Bytes: 1452
Flags: ACK
```

Refer to the exhibit. What does this syslog message indicate?

Exhibit

%SEC-6-IPACCESSLOGP: list inbound denied tcp 192.0.2.10(12345) -> 10.0.1.1(22), 1 packet
Question 15mediummultiple choice
Study the full ACL explanation →

Refer to the exhibit. A security analyst reviews the ACL configuration applied outbound on the external interface. Which statement is true about traffic from the 192.168.1.0/24 network to the internet?

Exhibit

Refer to the exhibit.

Extended ACL 101:
10 permit tcp 192.168.1.0 0.0.0.255 any eq 80
20 permit tcp 192.168.1.0 0.0.0.255 any eq 443
30 deny tcp any any eq 22
40 permit ip any any

Interface GigabitEthernet0/0:
 ip access-group 101 out

These 200-201 practice questions are part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style 200-201 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.