
CiscoCertified CyberOps Associate
Domain 3Objective 7
3.7 200-201 Practice Questions (Page 5)
Part of the 3.0 Host-Based Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 59 practice questions to prepare you well beyond it. (estimate)
59questions here
12free pages
12concepts
20%of the exam
Questions 21–25
- 21
An analyst is correlating events from multiple sources to reconstruct an attack. The following events are observed: 09:00 - User receives a phishing email; 09:05 - User clicks a link; 09:10 - Host makes an outbound connection to a suspicious IP; 09:15 - A new scheduled task is created. Which event is the best indicator of persistence?
Select an answer first - 22
A firewall log shows a connection from an internal workstation to an external IP on TCP port 4444. The Windows Security log on the workstation shows a successful logon with a new account name that the analyst does not recognize. Which action is most appropriate?
Select an answer first - 23
A company wants to centralize log collection from Windows workstations, Linux servers, and network firewalls for security analysis. The security team needs to correlate events across these sources. Which approach best meets this requirement?
Select an answer first - 24
Which hash algorithm is considered cryptographically broken and should not be used for security purposes, though it may still appear in legacy systems?
Select an answer first - 25
A security analyst is investigating a suspicious executable found on a Windows workstation. The analyst computes a SHA-256 hash of the file and compares it to the hash recorded in the organization's software inventory. The hashes match. However, the analyst notices that the file's creation timestamp is recent and the file is located in a user's Downloads folder, not the standard software deployment path. What is the most appropriate conclusion from this evidence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.