
CiscoCertified CyberOps Associate
Domain 1Objective 4
1.4 Compare Security Concepts 200-201 Practice Questions (Page 7)
Part of the 1.0 Security Concepts domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
7concepts
20%of the exam
Questions 31–35
- 31
A security analyst is performing a risk assessment for a new online payment system. The analyst has identified the payment system as a critical asset, identified that a cybercriminal group could attempt to steal payment data, and identified that the system has a vulnerability in its encryption implementation. What is the next step in the risk assessment process?
Select an answer first - 32
A security team is prioritizing vulnerabilities found in a web application. They have identified three risks: Risk A has a likelihood score of 8 and an impact score of 2. Risk B has a likelihood score of 5 and an impact score of 5. Risk C has a likelihood score of 2 and an impact score of 9. The team uses a simple multiplication of likelihood and impact to score risks. Which risk should be addressed first?
Select an answer first - 33
A security analyst is investigating an alert. The alert shows that an attacker sent a specially crafted packet to a network service, which caused the service to crash. The analyst determines that the service had a buffer overflow vulnerability. Which term best describes the specially crafted packet?
Select an answer first - 34
A security analyst notices that a competitor's website has been defaced with a political message. The attacker appears to be motivated by ideological beliefs rather than financial gain. Which type of threat actor is most likely responsible?
Select an answer first - 35
A web application firewall (WAF) logs show repeated attempts to exploit a SQL injection vulnerability in a legacy application. The application is scheduled for replacement in six months. The security team has confirmed that the WAF is effectively blocking all exploit attempts. Which statement best describes the relationship between the threat, vulnerability, and risk in this scenario?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.