Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 4Objective 3

4.3 Compare Deep Packet Inspection with Packet Filtering and Stateful Firewall Operation 200-201 Practice Questions (Page 4)

Part of the 4.0 Network Intrusion Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)

35questions here
7free pages
4concepts
20%of the exam

Questions 16–20

  1. 16application · easy

    A small office uses a firewall that only inspects packet headers. The administrator wants to allow inbound SSH from a specific remote office IP address while blocking all other inbound SSH. Which configuration will achieve this?

    Select an answer first
  2. 17application · medium

    A security team wants to detect data exfiltration attempts where sensitive files are being sent via HTTP POST requests to a cloud storage service. The team has access to a network tap and can deploy a monitoring tool. Which approach is best suited for this detection?

    Select an answer first
  3. 18application · medium

    A security analyst observes that a stateful firewall is allowing inbound packets that appear to be responses to internal requests, but the internal host never initiated such requests. What is the most likely explanation for this behavior?

    Select an answer first
  4. 19application · medium

    A network administrator wants to allow outbound web requests from internal users but block unsolicited inbound traffic. The firewall must automatically permit return traffic for established connections without requiring manual rules for each response. Which firewall operation meets this requirement?

    Select an answer first
  5. 20expert · hard

    A network administrator is troubleshooting a firewall issue. The firewall is configured to allow inbound TCP port 22 (SSH) to a management server. Users report that they can initiate SSH connections, but the sessions drop after a few seconds. The firewall logs show that inbound packets are being allowed, but outbound packets from the server are being dropped. The firewall is a stateful firewall. What is the most likely cause?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.