Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 4Objective 5

4.5 Compare the Characteristics of Data Obtained from Taps or Traffic Monitoring and Transactional Data (NetFlow) in the Analysis of Network Traffic 200-201 Practice Questions (Page 8)

Part of the 4.0 Network Intrusion Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
5concepts
20%of the exam

Questions 36–40

  1. 36application · medium

    A security analyst needs to identify all internal hosts that communicated with a known malicious IP over the past week. The analyst has access to NetFlow data and full packet capture from a TAP. Which data source should be used first to quickly identify the hosts?

    Select an answer first
  2. 37foundation · easy

    When comparing data obtained from a network TAP versus a SPAN port, which characteristic is unique to a TAP?

    Select an answer first
  3. 38application · medium

    A SOC analyst is reviewing network traffic to identify which internal hosts are communicating with a known malicious external IP. The analyst needs to see the volume of traffic (packets and bytes) and the duration of each connection, but does not need the actual content of the communication. Which data source is most appropriate for this task?

    Select an answer first
  4. 39foundation · easy

    Why does NetFlow require less storage and processing resources compared to full packet capture?

    Select an answer first
  5. 40expert · hard

    A security analyst is investigating a zero-day exploit that uses a previously unknown protocol over port 443. The analyst has NetFlow records and a full packet capture from a TAP for the same time period. The analyst needs to determine the exact payload structure of the exploit to create a detection signature. Which data source should the analyst use, and why?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to 200-201

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.