
CiscoCertified CyberOps Associate
Domain 3Objective 7
3.7 200-201 Practice Questions (Page 7)
Part of the 3.0 Host-Based Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 59 practice questions to prepare you well beyond it. (estimate)
59questions here
12free pages
12concepts
20%of the exam
Questions 31–35
- 31
An analyst is investigating a potential malware infection. The firewall log shows repeated outbound connections to a known malicious IP on port 53 (DNS). The Windows Event log shows a process named 'svchost.exe' running from a non-standard path (C:\Users\Public\svchost.exe). The analyst also sees a scheduled task that runs this process at system startup. What is the most likely explanation?
Select an answer first - 32
A Windows host's Security log shows Event ID 4624 (successful logon) for user 'admin' at 02:00 from an IP address that is not in the company's known range. The same host also shows Event ID 4688 for a process named 'cmd.exe' at 02:01. The analyst suspects lateral movement. Which additional evidence would most strongly support this hypothesis?
Select an answer first - 33
An organization maintains a file integrity monitoring (FIM) system that stores SHA-256 hashes of critical system files. During a routine check, the FIM reports that a critical executable's hash has changed. The analyst verifies the new hash against the vendor's official release notes and finds that the vendor released a security patch that updated the executable. What is the most appropriate conclusion?
Select an answer first - 34
A firewall log shows a connection from a host to an external IP on port 53 (DNS). The host's DNS log shows a query for 'update.example.com' at the same time. The host's process log shows 'svchost.exe' making the connection. The analyst must determine if this is malicious. What is the most important next step?
Select an answer first - 35
A company is deploying a SIEM and needs to collect logs from Windows workstations, Linux servers, and network firewalls. The security team has limited resources and wants to prioritize log sources that provide the most security-relevant information. Which log source should be prioritized first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.