Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 2Objective 8

2.8 Describe Endpoint-Based Attacks, Such as Buffer Overflows, Command and Control (C2), Malware, and Ransomware 200-201 Practice Questions (Page 1)

Part of the 2.0 Security Monitoring domain, which accounts for 25% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)

51questions here
11free pages
8concepts
25%of the exam

Questions 1–5

  1. 1foundation · easy

    In a typical ransomware attack, what happens immediately after the ransomware encrypts the victim's files?

    Select an answer first
  2. 2application · medium

    A vulnerability scanner reports that a web application has a buffer overflow in a function that processes user input. The application is running on a server with ASLR and DEP enabled. Which statement best describes the likely impact and the need for further analysis?

    Select an answer first
  3. 3expert · hard

    A security analyst is reviewing a vulnerability report for a custom application. The report states that a buffer overflow exists in a function that is called with user-controlled input. The application is running on a system with ASLR, DEP, and stack canaries enabled. The analyst must decide whether to prioritize this vulnerability for patching. Which consideration is most important?

    Select an answer first
  4. 4application · medium

    During an incident investigation, an analyst observes that a compromised host is sending DNS queries to a domain that resolves to a server controlled by the attacker. The queries contain encoded data in the subdomain labels. The analyst also sees that the host receives TXT record responses that contain commands. Which statement best describes this C2 communication technique?

    Select an answer first
  5. 5foundation · easy

    Which action is typically performed by an attacker using C2 infrastructure?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.