Courseiva

200-201 · topic practice

Security Monitoring practice questions

Security Monitoring is 25% of the Cisco CyberOps Associate 200-201 exam. It covers collecting and analyzing telemetry with SIEM correlation rules, NetFlow, and Cisco tools like Firepower, Stealthwatch, and Umbrella, plus interpreting logs from Zeek, syslog, and Windows events to detect intrusions and validate indicators of compromise.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Security Monitoring

What the exam tests

What to know about Security Monitoring

Be able to select the right data source and log, write correlation logic that thresholds repeated events over time, and distinguish true IoCs from benign artifacts. The most important thing: correlate multiple events, not single alerts, to confirm attacks like brute force.

Writing SIEM correlation rules that aggregate repeated failed logins into brute-force alerts

Reading Zeek http.log fields: HTTP methods, URIs, status codes, user agents

Using NetFlow and Cisco Stealthwatch to spot anomalous traffic flows and exfiltration

Recognizing valid IoCs such as file hashes, malicious domains, and IP addresses

Watch out for

Common Security Monitoring exam traps

  • ▸Treating a single failed login as a brute-force indicator instead of correlating many attempts within a time window
  • ▸Confusing Zeek log types, for example expecting HTTP details in conn.log rather than http.log
  • ▸Assuming any suspicious-looking artifact is an IoC without verifying it is actionable and observable evidence

Practice set

Security Monitoring questions

20 questions · select your answer, then reveal the explanation

During a security incident, a SOC analyst reviews NetFlow records and notices a single internal host communicating with a remote server on TCP port 443, sending 50 MB of data in 5 minutes, while the usual baseline for that host is 1 MB per hour. Which type of activity is most likely indicated?

While analyzing a PCAP file in Wireshark, an analyst sees multiple GET requests to /login.php with different usernames in the URL parameters, all from the same source IP: 192.168.1.100 to 10.0.0.1. The HTTP response codes are mostly 200 OK. This pattern suggests which attack?

Which Wireshark display filter would an analyst use to view only HTTP packets that contain the word 'password' in the packet payload?

During an incident response, an analyst extracts a suspicious file and computes its MD5 hash: d41d8cd98f00b204e9800998ecf8427e. Upon checking a threat intelligence feed, this hash is known as a malicious indicator. What does this hash represent?

A SOC analyst is reviewing a large number of alerts from a SIEM. Which THREE of the following are effective steps to prioritize and investigate alerts in a high-volume environment? (Choose three.)

During packet analysis, an analyst notices a TCP connection with a large number of SYN packets sent to various ports on a single host but no completed handshakes. This is characteristic of which activity?

Question 7mediummulti select
Read the full DNS explanation →

An analyst is reviewing DNS logs and sees a high volume of NXDOMAIN responses for a specific domain. Which TWO scenarios could this indicate?

In Wireshark, a security analyst wants to display only packets with source IP 10.0.0.1 and destination port 80. Which display filter should be used?

A security analyst needs to filter packets in Wireshark to capture only traffic on port 443. Which filter should be used?

In Snort, a rule is written as: alert tcp $EXTERNAL_NET any -> $HOME_NET 445 (msg:"SMB exploit attempt"; flow:to_server; content:"|ff|SMB"; nocase;). What does the 'flow:to_server' option indicate?

A security analyst is reviewing web server logs and notices a high number of 404 errors for non-existent URLs. Which TWO of the following tools would best help investigate this anomaly?

An analyst detects an internal host communicating with an external IP known for malware distribution. Which THREE of the following are valid Indicators of Compromise (IoCs) that should be recorded?

A SOC analyst is investigating a web server log and sees the following entry: 192.168.1.10 - - [15/May/2023:10:15:30 +0000] 'POST /login.php HTTP/1.1' 200 1245 'http://example.com/login.php' 'Mozilla/5.0'. Which observation is most suspicious?

A security analyst is using Wireshark to capture traffic from a network segment. They want to see only packets that contain the string 'password' in the payload. Which type of filter should they apply?

During a security investigation, an analyst examines a PCAP file in Wireshark. The analyst wants to see only traffic between two specific IP addresses (192.168.1.10 and 10.0.0.5). Which display filter should be applied?

Which log type would an analyst examine to see failed login attempts to a Windows server?

A security analyst is using Zeek to monitor network traffic. The analyst wants to extract all files transferred over HTTP. Which Zeek script or package accomplishes this?

Question 18mediummultiple choice
Read the full DNS explanation →

A SOC analyst observes a spike in DNS queries for long, random-looking subdomains under a single domain from an internal host. The responses are NXDOMAIN. Which type of activity is most likely indicated?

A SOC analyst is investigating a potential data exfiltration incident. Which TWO Indicators of Compromise (IoCs) would be most relevant for tracking the exfiltration of files over the network?

A security analyst is tuning a Snort IDS to reduce false positives. Which TWO Snort rule options should the analyst modify to make the rule more specific?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Security Monitoring sessions

Start a Security Monitoring only practice session

Every question in these sessions is drawn from the Security Monitoring domain — nothing else.

Related practice questions

Related 200-201 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 200-201 exam test about Security Monitoring?
Be able to select the right data source and log, write correlation logic that thresholds repeated events over time, and distinguish true IoCs from benign artifacts. The most important thing: correlate multiple events, not single alerts, to confirm attacks like brute force.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Security Monitoring questions in a focused session?
Yes — the session launcher on this page draws every question from the Security Monitoring domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 200-201 topics?
Use the topic links above to move to related areas, or go back to the 200-201 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 200-201 exam covers. They are not copied from any real exam or dump site.