Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 2Objective 9

2.9 Describe Evasion and Obfuscation Techniques, Such as Tunneling, Encryption, and Proxies 200-201 Practice Questions (Page 2)

Part of the 2.0 Security Monitoring domain, which accounts for 25% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)

27questions here
6free pages
3concepts
25%of the exam

Questions 6–10

  1. 6application · medium

    A network administrator notices that an internal host is communicating with an external server using SSH on port 22, but the traffic volume is unusually high and the session lasts for hours. The administrator suspects the host is using SSH to tunnel other traffic. Which technique is the host using?

    Select an answer first
  2. 7expert · hard

    A security analyst is trying to determine whether a user is using a proxy to bypass the corporate web filter. The analyst sees HTTPS traffic to a known proxy service. However, the corporate firewall is configured to allow HTTPS traffic. Which additional evidence would most strongly indicate that the user is using the proxy to evade the filter?

    Select an answer first
  3. 8foundation · easy

    Which type of proxy is specifically designed to hide the client's IP address from the destination server?

    Select an answer first
  4. 9application · medium

    An organization's security team has noticed that a user's workstation is making HTTPS connections to a cloud-based proxy service that is not on the approved list. The proxy service is known to allow users to bypass content filtering. The team suspects the user is using this proxy to hide web traffic from the corporate security controls. Which two techniques are being combined in this scenario?

    Select an answer first
  5. 10application · medium

    A security analyst notices that a workstation is sending large volumes of DNS queries to an external server. The queries contain encoded data in the subdomain labels. The analyst suspects the workstation is using DNS as a covert channel. Which technique is the workstation most likely using?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.