Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 1Objective 11

1.11 Compare Rule-Based Detection vs. Behavioral and Statistical Detection 200-201 Practice Questions (Page 5)

Part of the 1.0 Security Concepts domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)

36questions here
8free pages
4concepts
20%of the exam

Questions 21–25

  1. 21application · medium

    A security analyst at a financial firm notices that the existing intrusion detection system generates a high volume of alerts for a known exploit, but the team is overwhelmed and misses a new variant of the exploit that uses a slightly different payload. The analyst wants to improve detection of both the known and new variants without significantly increasing false positives. Which approach should the analyst implement?

    Select an answer first
  2. 22application · medium

    An analyst notices that a user account that normally logs in from 9 AM to 5 PM has suddenly started logging in at 2 AM and downloading large amounts of data. The activity does not match any known attack signature. Which detection method is most likely to flag this activity?

    Select an answer first
  3. 23expert · hard

    A security team is evaluating detection methods for a network that experiences frequent false positives from rule-based detection due to legitimate traffic that resembles attack patterns. They also need to detect a new insider threat that involves a user slowly exfiltrating data over several weeks. The team has limited resources for tuning detection systems. Which approach best balances the need to reduce false positives and detect the slow exfiltration?

    Select an answer first
  4. 24expert · hard

    A security team is designing a detection strategy for a large enterprise with a mix of known and unknown threats. The team has limited resources and cannot afford to investigate every alert. They need to prioritize alerts that are most likely to indicate a real attack. Which strategy best balances detection coverage and alert volume?

    Select an answer first
  5. 25foundation · easy

    A security system uses a mathematical model to compute the probability of a network event and alerts when the probability falls below a certain threshold. Which detection method is being used?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.