
CiscoCertified CyberOps Associate
Domain 5Objective 10
5.10 Classify Intrusion Events into Categories as Defined by Security Models, Such as Cyber Kill Chain Model and Diamond Model of Intrusion 200-201 Practice Questions (Page 5)
Part of the 5.0 Security Policies and Procedures domain, which accounts for 15% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
5concepts
15%of the exam
Questions 21–23
- 21
An analyst observes a user receiving a phishing email with a malicious attachment. According to the Cyber Kill Chain, which phase does this event represent?
Select an answer first - 22
A security analyst is writing a report on a recent intrusion. The analyst wants to show the sequence of events from initial reconnaissance to data exfiltration, highlighting the steps the attacker took. Which model is best suited for this narrative?
Select an answer first - 23
An analyst is investigating an alert where an attacker sent a crafted PDF file to a user. The user opened the PDF, which exploited a vulnerability in the PDF reader and installed a backdoor. According to the Cyber Kill Chain, which phase is the exploitation of the PDF reader vulnerability?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to 200-201
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.