
CiscoCertified CyberOps Associate
Domain 2Objective 8
2.8 Describe Endpoint-Based Attacks, Such as Buffer Overflows, Command and Control (C2), Malware, and Ransomware 200-201 Practice Questions (Page 4)
Part of the 2.0 Security Monitoring domain, which accounts for 25% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
8concepts
25%of the exam
Questions 16–20
- 16
A user reports that their computer is running slowly and displaying pop-ups. The security team finds a program that was installed alongside a free software download. The program is not malicious by itself but displays advertisements. Which type of malware is this?
Select an answer first - 17
A security analyst is monitoring network traffic and notices that a host is sending small, periodic DNS queries to a domain that is not in any threat intelligence feed. The queries are for A records, and the responses contain data that is not typical for DNS. The analyst suspects DNS tunneling. Which additional evidence would most strongly confirm DNS tunneling?
Select an answer first - 18
A security analyst is reviewing network logs and sees that a workstation is communicating with an external IP address on port 443 at regular intervals. The traffic is encrypted and the destination is a known malicious IP. The analyst suspects the workstation is compromised. Which behavior is most indicative of C2 communication?
Select an answer first - 19
A company has experienced a ransomware attack that encrypted files on a network share. The IT team has offline backups, but the last backup was 24 hours old. The company's leadership is considering paying the ransom to get the decryption key. Which factor should the security team emphasize in their recommendation?
Select an answer first - 20
A company's endpoint protection alerts on a file that is attempting to access the Windows Registry and create a run key. The file was downloaded from a malicious website. Which stage of the ransomware lifecycle is this activity most associated with?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.