Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 2Objective 8

2.8 Describe Endpoint-Based Attacks, Such as Buffer Overflows, Command and Control (C2), Malware, and Ransomware 200-201 Practice Questions (Page 5)

Part of the 2.0 Security Monitoring domain, which accounts for 25% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)

51questions here
11free pages
8concepts
25%of the exam

Questions 21–25

  1. 21application · medium

    A security analyst is reviewing a crash dump from a legacy Windows application that processes user-supplied filenames. The crash occurs when a filename longer than 260 characters is passed to a function that copies it into a fixed 128-byte buffer. The analyst notices that the return address of the function was overwritten with data from the filename. Which type of endpoint attack is this an example of, and what is the most likely immediate impact?

    Select an answer first
  2. 22application · medium

    A company's files are encrypted by ransomware. The ransom note demands payment in Bitcoin and threatens to delete the decryption key if payment is not made within 72 hours. The company has offline backups that were last tested a month ago. What is the best course of action?

    Select an answer first
  3. 23application · medium

    A hospital's IT team discovers that a workstation downloaded a malicious document from a phishing email. Within hours, files on the network share are encrypted with a .enc extension, and a ransom note demands payment in cryptocurrency. The team also notices that the malware attempted to delete Volume Shadow Copies. Which stage of the ransomware attack lifecycle is the deletion of shadow copies part of, and why?

    Select an answer first
  4. 24expert · medium

    A security analyst is investigating a host that is suspected of C2 communication. The analyst sees that the host is making HTTPS connections to a website that hosts a blog. The traffic is encrypted, and the analyst cannot see the content. Which technique could the attacker be using to hide C2 traffic in plain sight?

    Select an answer first
  5. 25expert · hard

    An incident responder is analyzing a host that is suspected of being part of a botnet. The host is making DNS queries to a domain that changes every hour. The domain names are random and do not appear in any threat intelligence feed. Which technique is the malware likely using, and what is the best way to disrupt it?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.