
CiscoCertified CyberOps Associate
Domain 4Objective 5
4.5 Compare the Characteristics of Data Obtained from Taps or Traffic Monitoring and Transactional Data (NetFlow) in the Analysis of Network Traffic 200-201 Practice Questions (Page 6)
Part of the 4.0 Network Intrusion Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
5concepts
20%of the exam
Questions 26–30
- 26
What is a key characteristic of NetFlow data compared to full packet capture?
Select an answer first - 27
A network engineer needs to capture traffic on a 1 Gbps full-duplex link to analyze a suspected malware infection. The switch supports SPAN and the engineer has access to a TAP. The engineer wants to ensure that both directions of the conversation are captured without dropping frames during peak utilization. Which approach should the engineer choose?
Select an answer first - 28
A security team is planning to capture traffic on a high-throughput data center link for forensic analysis. They have a limited budget for storage and processing. The team needs to retain data for 90 days and be able to reconstruct the exact sequence of packets for a specific incident. Which approach best balances the storage constraint with the forensic requirement?
Select an answer first - 29
A security analyst is investigating a potential command-and-control (C2) communication. The analyst needs to identify which internal hosts are communicating with a known C2 server and how much data is being transferred, but does not need to see the actual commands. Which data source is most efficient for this investigation?
Select an answer first - 30
A network engineer is asked to provide evidence of a security breach that involved malformed Ethernet frames and a half-open connection. The analyst needs to see the exact frames, including any CRC errors, to prove the attack. The switch is heavily loaded and SPAN is available, but the engineer is concerned about dropped frames. Which data source should be chosen?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.