Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 2Objective 8

2.8 Describe Endpoint-Based Attacks, Such as Buffer Overflows, Command and Control (C2), Malware, and Ransomware 200-201 Practice Questions (Page 2)

Part of the 2.0 Security Monitoring domain, which accounts for 25% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)

51questions here
11free pages
8concepts
25%of the exam

Questions 6–10

  1. 6expert · hard

    A company's security team is reviewing their ransomware response plan. They have a mix of on-premises servers and cloud-based file storage. The plan includes regular backups, but the backups are stored on the same network as the production servers. Which improvement would most effectively reduce the impact of a ransomware attack?

    Select an answer first
  2. 7application · medium

    A security analyst is reviewing an alert about a user who downloaded a file from a website that was compromised. The file appeared to be a PDF but actually contained executable code that installed a backdoor. Which infection vector best describes this scenario?

    Select an answer first
  3. 8application · medium

    A developer reports that a legacy C application crashes when processing a specially crafted input file. The crash occurs because the application copies the file contents into a fixed-size stack buffer without validating the length. A security analyst is asked to explain the likely root cause. Which description best matches the vulnerability?

    Select an answer first
  4. 9expert · medium

    A security analyst is reviewing a vulnerability report for a web application. The report states that a buffer overflow exists in a function that processes user-supplied input. The analyst must decide which mitigation is most effective to prevent exploitation of this vulnerability. Which approach is the most reliable?

    Select an answer first
  5. 10expert · hard

    A security operations center (SOC) is investigating a host that is beaconing to a domain that was recently registered and has a low reputation. The beaconing uses HTTP with a unique User-Agent string. The SOC wants to block the C2 traffic without disrupting legitimate web browsing. Which approach is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.