Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 4Objective 3

4.3 Compare Deep Packet Inspection with Packet Filtering and Stateful Firewall Operation 200-201 Practice Questions (Page 2)

Part of the 4.0 Network Intrusion Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)

35questions here
7free pages
4concepts
20%of the exam

Questions 6–10

  1. 6expert · hard

    A security analyst is troubleshooting why a firewall is allowing a specific application that should be blocked. The firewall is configured with stateful inspection and packet filtering rules, but not DPI. The application uses a non-standard port and is not blocked by any IP rule. Which is the most likely reason the application is allowed?

    Select an answer first
  2. 7foundation · easy

    What is a security implication of using packet filtering instead of a stateful firewall?

    Select an answer first
  3. 8application · medium

    A company is choosing a security device to enforce a policy that blocks peer-to-peer file sharing traffic, regardless of the port or protocol used. The policy must also allow all other internet traffic. Which technology is most appropriate for this requirement?

    Select an answer first
  4. 9application · medium

    A security analyst needs to detect a malware variant that sends a specific pattern in the payload of otherwise normal-looking HTTP requests. The firewall currently performs packet filtering only. Which technology should be added to detect this pattern?

    Select an answer first
  5. 10application · medium

    A small company wants to replace its legacy packet-filtering firewall with a solution that can block inbound connections that are not part of an existing outbound session, while also allowing legitimate responses to return. The company has a limited budget and does not need application-level inspection. Which solution best meets the requirement?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.