
CiscoCertified CyberOps Associate
Domain 2Objective 8
2.8 Describe Endpoint-Based Attacks, Such as Buffer Overflows, Command and Control (C2), Malware, and Ransomware 200-201 Practice Questions (Page 6)
Part of the 2.0 Security Monitoring domain, which accounts for 25% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
8concepts
25%of the exam
Questions 26–30
- 26
Why do attackers often use HTTP or HTTPS for C2 communication?
Select an answer first - 27
Which technique is commonly used by malware to evade detection during C2 communication?
Select an answer first - 28
What is an exploit kit?
Select an answer first - 29
What is the fundamental cause of a buffer overflow vulnerability?
Select an answer first - 30
A company has been hit by ransomware. The security team discovers that the ransomware was able to encrypt files on network shares because the service account used by the backup software had write access to those shares. The team is now designing a recovery plan. Which change would most reduce the impact of a future ransomware attack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.