
CiscoCertified CyberOps Associate
Domain 2Objective 8
2.8 Describe Endpoint-Based Attacks, Such as Buffer Overflows, Command and Control (C2), Malware, and Ransomware 200-201 Practice Questions (Page 2)
Part of the 2.0 Security Monitoring domain, which accounts for 25% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
8concepts
25%of the exam
Questions 6–10
- 6
A company's security team is reviewing their ransomware response plan. They have a mix of on-premises servers and cloud-based file storage. The plan includes regular backups, but the backups are stored on the same network as the production servers. Which improvement would most effectively reduce the impact of a ransomware attack?
Select an answer first - 7
A security analyst is reviewing an alert about a user who downloaded a file from a website that was compromised. The file appeared to be a PDF but actually contained executable code that installed a backdoor. Which infection vector best describes this scenario?
Select an answer first - 8
A developer reports that a legacy C application crashes when processing a specially crafted input file. The crash occurs because the application copies the file contents into a fixed-size stack buffer without validating the length. A security analyst is asked to explain the likely root cause. Which description best matches the vulnerability?
Select an answer first - 9
A security analyst is reviewing a vulnerability report for a web application. The report states that a buffer overflow exists in a function that processes user-supplied input. The analyst must decide which mitigation is most effective to prevent exploitation of this vulnerability. Which approach is the most reliable?
Select an answer first - 10
A security operations center (SOC) is investigating a host that is beaconing to a domain that was recently registered and has a low reputation. The beaconing uses HTTP with a unique User-Agent string. The SOC wants to block the C2 traffic without disrupting legitimate web browsing. Which approach is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.