Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 4Objective 5

4.5 Compare the Characteristics of Data Obtained from Taps or Traffic Monitoring and Transactional Data (NetFlow) in the Analysis of Network Traffic 200-201 Practice Questions (Page 5)

Part of the 4.0 Network Intrusion Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
5concepts
20%of the exam

Questions 21–25

  1. 21foundation · easy

    Which type of data provides a more granular view of individual network conversations?

    Select an answer first
  2. 22application · medium

    A security analyst is investigating a potential data exfiltration incident. The analyst needs to determine which internal hosts communicated with a known external command-and-control server over the past 30 days, including the total bytes transferred per conversation. The analyst has access to NetFlow records stored on a collector. Which type of analysis is most appropriate?

    Select an answer first
  3. 23application · medium

    A SOC analyst is monitoring a network for signs of a distributed denial-of-service (DDoS) attack. The analyst needs to identify the source IPs generating the most traffic and the duration of each flow, but does not need to inspect the payload. Which data source is best suited for this analysis?

    Select an answer first
  4. 24foundation · easy

    Which analysis task is best suited for full packet capture from a TAP?

    Select an answer first
  5. 25expert · hard

    A SOC manager must choose a monitoring solution for a 40 Gbps backbone link. The solution must support both long-term traffic trend analysis and deep packet inspection for incident response. The budget allows for either a high-capacity NetFlow collector or a packet capture appliance with limited retention. Which combination of data sources would best meet both requirements?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.