Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 2Objective 8

2.8 Describe Endpoint-Based Attacks, Such as Buffer Overflows, Command and Control (C2), Malware, and Ransomware 200-201 Practice Questions (Page 3)

Part of the 2.0 Security Monitoring domain, which accounts for 25% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)

51questions here
11free pages
8concepts
25%of the exam

Questions 11–15

  1. 11application · medium

    A user receives an email with an attachment named 'Invoice_Q3.exe'. The user runs it, and the executable installs a backdoor that connects to an external server. Later, the server sends commands that download additional malware. Which infection vector and malware type are demonstrated?

    Select an answer first
  2. 12application · medium

    During an incident response, an analyst finds that a compromised host is communicating with a server using HTTPS on port 443. The traffic is encrypted, and the analyst cannot see the payload. Which technique would most likely help the analyst identify the C2 traffic?

    Select an answer first
  3. 13expert · medium

    A security analyst is analyzing a crash dump from a server. The crash occurred after the server received a malformed network packet. The analyst finds that the packet contained a long string that overwrote a return address on the stack. Which statement best describes the likely impact and next step?

    Select an answer first
  4. 14foundation · easy

    What is a primary characteristic of a Trojan horse?

    Select an answer first
  5. 15application · medium

    A security analyst is investigating a server that was compromised through a vulnerable network service. The analyst finds that the attacker sent a payload longer than the service's input buffer, and the service then executed instructions from the payload. Which type of attack is this?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.