Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 4Objective 3

4.3 Compare Deep Packet Inspection with Packet Filtering and Stateful Firewall Operation 200-201 Practice Questions (Page 3)

Part of the 4.0 Network Intrusion Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)

35questions here
7free pages
4concepts
20%of the exam

Questions 11–15

  1. 11expert · hard

    A firewall administrator notices that a stateful firewall is allowing inbound TCP packets that do not match any existing connection in the state table. The packets have the ACK flag set. What is the most likely cause and the best corrective action?

    Select an answer first
  2. 12expert · hard

    A network administrator is configuring a firewall for a small business that uses a legacy application that sends data over a fixed UDP port. The application requires that the firewall allow inbound UDP packets to the server only if the server recently sent an outbound packet to the same client. The administrator wants to implement this with minimal configuration. Which approach is most appropriate?

    Select an answer first
  3. 13expert · hard

    A security engineer is designing a firewall policy for a DMZ that hosts a public web server. The policy must allow inbound HTTPS traffic to the web server and allow the web server to initiate outbound connections to a database server on an internal network. The engineer wants to minimize the number of rules and ensure that only legitimate responses to inbound HTTPS requests are allowed back to external clients. Which firewall approach is most appropriate?

    Select an answer first
  4. 14application · medium

    A network administrator needs to block all traffic from a specific source IP address on a firewall that only supports packet filtering. The firewall should still allow all other traffic. Which rule should be configured?

    Select an answer first
  5. 15application · medium

    A network administrator wants to allow internal users to access external websites, but block all inbound connection attempts from the internet. The firewall must automatically permit responses to the internal users' requests. Which firewall configuration is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.