Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 1Objective 11

1.11 Compare Rule-Based Detection vs. Behavioral and Statistical Detection 200-201 Practice Questions (Page 2)

Part of the 1.0 Security Concepts domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)

36questions here
8free pages
4concepts
20%of the exam

Questions 6–10

  1. 6application · medium

    An organization has a high rate of false positives from its current detection system. The system flags legitimate users who occasionally access the network from new locations. The team wants to reduce false positives while still detecting compromised accounts. Which approach is most appropriate?

    Select an answer first
  2. 7application · medium

    A security analyst is monitoring network traffic and wants to detect a slow and low data exfiltration attack that transfers small amounts of data over a long period. The analyst has no prior knowledge of the attack. Which detection method is most likely to identify this activity?

    Select an answer first
  3. 8application · medium

    A security team wants to detect a new ransomware strain that encrypts files in a pattern never seen before. They also need to reduce false positives from legitimate users who occasionally work late. Which detection strategy best addresses both needs?

    Select an answer first
  4. 9expert · hard

    A security operations center (SOC) is implementing a new detection strategy. The SOC has a small team and cannot investigate all alerts. They want to reduce alert fatigue while maintaining the ability to detect unknown threats. Which approach is most effective?

    Select an answer first
  5. 10foundation · easy

    A security team deploys a system that learns normal user login times and flags logins at unusual hours. Which detection method does this describe?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.