
CiscoCertified CyberOps Associate
Domain 1Objective 11
1.11 Compare Rule-Based Detection vs. Behavioral and Statistical Detection 200-201 Practice Questions (Page 6)
Part of the 1.0 Security Concepts domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
4concepts
20%of the exam
Questions 26–30
- 26
A security analyst needs to detect insider threats where an employee accesses files at unusual times and downloads large amounts of data. Which detection method is best suited for this scenario?
Select an answer first - 27
A security team is investigating a series of alerts from a behavioral detection system. The system has flagged a user who is accessing files from a new location and at unusual times. The user is a remote worker who frequently travels. Which factor is most important in determining whether these alerts are true positives?
Select an answer first - 28
What is the primary advantage of behavioral detection over rule-based detection?
Select an answer first - 29
A security analyst is reviewing alerts from a network-based intrusion detection system (NIDS). The NIDS uses a signature database that is updated weekly. The analyst notices that the NIDS is not detecting a new malware variant that was released yesterday. Which limitation of rule-based detection does this scenario illustrate?
Select an answer first - 30
Which characteristic is a primary limitation of rule-based (signature-based) detection?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.