Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 2Objective 9

2.9 Describe Evasion and Obfuscation Techniques, Such as Tunneling, Encryption, and Proxies 200-201 Practice Questions (Page 1)

Part of the 2.0 Security Monitoring domain, which accounts for 25% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)

27questions here
6free pages
3concepts
25%of the exam

Questions 1–5

  1. 1application · medium

    A security analyst is analyzing network traffic and sees that a compromised host is sending encrypted data to an external server on port 443. The analyst cannot inspect the content of the traffic. Which evasion technique is the attacker using to hide the malicious communication?

    Select an answer first
  2. 2foundation · easy

    How can a proxy be used to evade detection by hiding the origin of traffic?

    Select an answer first
  3. 3application · medium

    A security analyst is examining network traffic and sees a large amount of HTTP traffic to an external server on port 80. The traffic is unusually high and the payload contains data that is not typical of HTTP requests. The analyst suspects the host is using HTTP as a covert channel. Which technique is being used?

    Select an answer first
  4. 4application · medium

    A security analyst is reviewing firewall logs and notices that an internal user is accessing a blocked website. The user's traffic appears to be coming from an external IP address that is not the user's workstation. The analyst suspects the user is using a web proxy to bypass the firewall. Which technique is the user employing?

    Select an answer first
  5. 5expert · hard

    A security analyst is investigating a malware infection. The malware is using a combination of encryption and proxy chaining to communicate with a C2 server. The analyst needs to identify the C2 server's IP address. The analyst has access to the firewall logs, which show the traffic going to a proxy server. Which action would be most effective in identifying the C2 server?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.