Courseiva

200-201 · topic practice

Security Concepts practice questions

Security Concepts is 20% of the Cisco CyberOps Associate 200-201 exam. It covers the CIA triad, threat actors and malware, attack types and vectors, social engineering, cryptographic fundamentals, and compliance frameworks such as PCI DSS, GDPR, HIPAA, and SOX. Questions are scenario-based: identify an attack, map traffic to a technique, or select the governing regulation.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Security Concepts

What the exam tests

What to know about Security Concepts

You must read a scenario and classify the attack, control, or regulation it describes, then justify the choice. The single most important skill is matching the specific detail in the question, such as cardholder data or EU citizens' data, to the correct framework or technique.

Classifying attacks like DDoS, reconnaissance, and social engineering from scenario descriptions

Mapping compliance frameworks (PCI DSS, GDPR, HIPAA) to stated data-protection requirements

Applying the CIA triad and identifying confidentiality, integrity, or availability impacts

Recognizing malware types, threat actor motivations, and cryptographic concepts like hashing and PKI

Watch out for

Common Security Concepts exam traps

  • ▸Confusing active reconnaissance (scanning, probing) with passive reconnaissance (traffic monitoring), which changes which traffic a firewall should block
  • ▸Mixing up compliance frameworks, such as choosing HIPAA instead of PCI DSS for cardholder data or GDPR for EU personal data
  • ▸Treating a DDoS attack as a single-source intrusion when the scenario describes many compromised systems flooding one target

Practice set

Security Concepts questions

20 questions · select your answer, then reveal the explanation

An organization is implementing a security policy to protect sensitive data. Which three are considered compliance frameworks that could guide this effort? (Choose three.)

An organization wants to ensure data integrity and non-repudiation for sensitive documents. Which THREE cryptographic mechanisms should be implemented? (Select three.)

A security analyst is reviewing network logs and identifies several failed login attempts followed by a successful login from an unusual geographic location. Which TWO security concepts are most directly related to this scenario? (Choose two.)

A company is implementing a new security policy to protect customer payment information. Which TWO compliance frameworks are most relevant to this requirement? (Choose two.)

An analyst is investigating a security incident where an attacker gained access to a server by exploiting a known vulnerability. The attacker then moved laterally and exfiltrated data. Which THREE phases of the Cyber Kill Chain are evident in this scenario? (Choose three.)

Which element of the CIA triad ensures that data cannot be modified by unauthorized parties?

A user receives an email that appears to be from the company's IT department asking for their password to perform a security check. The email contains a link to a fake login page. Which type of social engineering attack is this?

A security engineer is analyzing a recent breach. The attacker gained access by sending an email that appeared to be from the CEO, requesting the recipient to transfer funds. What type of social engineering attack is this?

An organization wants to ensure that a message has not been altered during transmission. Which cryptographic technique should be used?

Question 10hardmultiple choice
Read the full DNS explanation →

A security analyst is investigating an incident where an attacker successfully altered DNS records to redirect users to a fake website. Which attack occurred?

Which element of the CIA triad ensures that data cannot be modified by unauthorized parties?

A security analyst discovers that an attacker has captured network traffic and used it to impersonate a legitimate user in a subsequent session. Which element of the CIA triad is most directly compromised in this scenario?

A security team is implementing a Public Key Infrastructure (PKI) to support digital signatures for email. Which THREE components are essential to the PKI framework? (Choose three.)

Question 14mediummultiple choice
Read the full Security Concepts explanation →

A security analyst notices that a user's workstation is repeatedly resolving a domain that closely resembles the company's legitimate internal payroll portal, but the domain is registered to an unfamiliar overseas registrar. The user reports being redirected to a page requesting credentials after clicking a link in a recent email. Which type of attack is most likely occurring?

Question 15mediummultiple choice
Read the full Security Concepts explanation →

A security team deploys a new web application and wants to classify the risk that an unauthenticated attacker could read the contents of the back-end database through a crafted input field. Which concept best describes the exposure being assessed?

A security analyst is investigating a recent security incident. The analyst discovers that an attacker gained initial access by exploiting a vulnerability in a public-facing web server. The attacker then moved laterally to a database server and exfiltrated sensitive data. Which phase of the Cyber Kill Chain does the lateral movement represent?

An analyst is examining a suspicious email attachment that appears to be a PDF invoice. Static analysis reveals embedded JavaScript that, when executed, uses the PDF reader's API to launch a command shell and download a payload from a remote server. The file's hash is not found in any signature database. Which malware evasion technique is most clearly demonstrated?

A security operations center (SOC) analyst is investigating a potential security incident. The analyst needs to determine whether the organization is compliant with the Payment Card Industry Data Security Standard (PCI DSS). Which TWO of the following are core requirements of PCI DSS? (Choose two.)

Question 19mediummultiple choice
Read the full Security Concepts explanation →

A security analyst is reviewing a packet capture from a compromised host and observes that the attacker's traffic to a command-and-control server is encoded to look like normal HTTPS but uses a self-signed certificate with an unusual Common Name. The analyst wants to classify this technique within the CIA triad impact. Which security concept does this scenario primarily illustrate?

An analyst is reviewing a packet capture and sees a host repeatedly sending TCP SYN packets to many different destination ports on a single target, but the host never completes the three-way handshake. Which type of attack is most consistent with this behavior?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Security Concepts sessions

Start a Security Concepts only practice session

Every question in these sessions is drawn from the Security Concepts domain — nothing else.

Related practice questions

Related 200-201 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 200-201 exam test about Security Concepts?
You must read a scenario and classify the attack, control, or regulation it describes, then justify the choice. The single most important skill is matching the specific detail in the question, such as cardholder data or EU citizens' data, to the correct framework or technique.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Security Concepts questions in a focused session?
Yes — the session launcher on this page draws every question from the Security Concepts domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 200-201 topics?
Use the topic links above to move to related areas, or go back to the 200-201 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 200-201 exam covers. They are not copied from any real exam or dump site.