
CiscoCertified CyberOps Associate
Domain 4Objective 5
4.5 Compare the Characteristics of Data Obtained from Taps or Traffic Monitoring and Transactional Data (NetFlow) in the Analysis of Network Traffic 200-201 Practice Questions (Page 4)
Part of the 4.0 Network Intrusion Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
5concepts
20%of the exam
Questions 16–20
- 16
A security analyst is investigating a data breach and needs to determine whether any sensitive data was transmitted to an external IP address. The analyst has NetFlow records for the past 60 days and a full packet capture for the past 24 hours. The breach may have occurred up to 30 days ago. Which approach is most effective?
Select an answer first - 17
An organization needs to monitor traffic on a 10 Gbps backbone link for a security analytics platform. The platform requires full payload visibility for intrusion detection, but the organization has limited storage capacity. Which approach would best meet the requirement while managing storage constraints?
Select an answer first - 18
A network team is troubleshooting a performance issue that may be caused by physical-layer errors on a critical link. They need to capture the actual frames to see if CRC errors are present. The switch has a SPAN port available, but the team is concerned that SPAN might not show physical-layer errors. Which approach should they take?
Select an answer first - 19
An organization is experiencing a security incident that involves both a network scan and a potential data breach. The analyst needs to identify the scanning pattern (which ports were probed) and also determine if any sensitive data was transmitted. The analyst has access to NetFlow and a TAP. Which approach should be taken?
Select an answer first - 20
A security analyst needs to investigate a suspected ARP spoofing attack that occurred on a switch segment. The analyst must capture the actual ARP packets exchanged between two hosts to confirm the attack. The switch supports SPAN and the network has an available TAP. Which data source should the analyst use to ensure the capture includes the full-duplex traffic and any physical-layer errors?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.