Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 2Objective 9

2.9 Describe Evasion and Obfuscation Techniques, Such as Tunneling, Encryption, and Proxies 200-201 Practice Questions (Page 4)

Part of the 2.0 Security Monitoring domain, which accounts for 25% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)

27questions here
6free pages
3concepts
25%of the exam

Questions 16–20

  1. 16application · medium

    A security analyst is examining network traffic and sees a large amount of ICMP echo requests and replies between an internal host and an external server. The payload of the ICMP packets contains data that is not typical of ping traffic. The analyst suspects the host is using ICMP as a covert channel. Which technique is being used?

    Select an answer first
  2. 17application · medium

    A security analyst is investigating a malware infection. The malware is configured to communicate with a command-and-control (C2) server using HTTP requests that are relayed through a series of compromised web servers. The malware's true C2 server address is not directly visible in the network traffic. Which evasion technique is the malware using?

    Select an answer first
  3. 18foundation · easy

    Which technique is an example of tunneling that could be used to evade network security monitoring?

    Select an answer first
  4. 19expert · hard

    A security analyst is investigating a malware infection. The malware is configured to use a proxy chain to communicate with a C2 server. The analyst sees traffic to the first proxy, but cannot see the final destination. Which technique is the malware using to hide the C2 server?

    Select an answer first
  5. 20application · medium

    A security analyst is investigating a compromised host that is sending data to an external server. The data is encapsulated in HTTP requests that are sent to a web server that the attacker controls. The HTTP requests appear to be normal web traffic, but the payload contains hidden data. Which evasion technique is being used?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.