Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 4Objective 5

4.5 Compare the Characteristics of Data Obtained from Taps or Traffic Monitoring and Transactional Data (NetFlow) in the Analysis of Network Traffic 200-201 Practice Questions (Page 2)

Part of the 4.0 Network Intrusion Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
5concepts
20%of the exam

Questions 6–10

  1. 6application · medium

    A small company has limited storage and processing resources. They need to monitor traffic patterns across their network for a month to identify unusual communication patterns, but they do not need to inspect payloads. Which approach best balances resource usage with the monitoring requirement?

    Select an answer first
  2. 7application · medium

    A SOC analyst is investigating a possible brute-force attack against an SSH server. The analyst wants to identify the source IP addresses that initiated the most connections and the total number of packets sent per source over the last hour. Which data source is best suited for this task?

    Select an answer first
  3. 8foundation · easy

    In which scenario would NetFlow data be more appropriate than full packet capture?

    Select an answer first
  4. 9expert · hard

    A network team is planning to deploy a monitoring solution for a critical link that carries both production traffic and management traffic. They need to capture all traffic, including any physical-layer errors, but they cannot afford to impact the link's performance. Which deployment method best meets these requirements?

    Select an answer first
  5. 10application · medium

    A SOC team needs to monitor a high-throughput network for anomalies. They have a limited budget and cannot afford a large storage system. They need to detect unusual traffic patterns, such as sudden spikes in traffic to a specific destination. Which data source is most cost-effective for this purpose?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.