
CiscoCertified CyberOps Associate
Domain 2Objective 9
2.9 Describe Evasion and Obfuscation Techniques, Such as Tunneling, Encryption, and Proxies 200-201 Practice Questions (Page 5)
Part of the 2.0 Security Monitoring domain, which accounts for 25% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
3concepts
25%of the exam
Questions 21–25
- 21
A network administrator notices that a server inside the DMZ is sending large volumes of DNS queries to an external DNS server. The queries contain long subdomains with random-looking strings. The administrator suspects DNS tunneling. Which action would best confirm this suspicion?
Select an answer first - 22
A security analyst is reviewing network traffic and sees that a host is making HTTPS connections to a cloud-based service that is known to be a proxy. The analyst suspects the user is using the proxy to bypass the corporate web filter. However, the corporate firewall is configured to allow HTTPS traffic. Which additional evidence would most strongly indicate that the user is using the proxy to evade the filter?
Select an answer first - 23
A security analyst is reviewing proxy logs and notices that a user is accessing a website that is blocked by the organization's web filter. The user's traffic appears to be coming from a proxy server that is not the organization's proxy. The analyst suspects the user is using a personal proxy to bypass the web filter. Which technique is the user employing?
Select an answer first - 24
A security analyst is investigating a malware infection. The malware is using HTTPS to communicate with a C2 server, and the analyst cannot inspect the traffic because it is encrypted. The analyst has access to the firewall logs, which show the traffic going to a known malicious domain. Which action would be most effective in disrupting the malware's communication?
Select an answer first - 25
A security analyst is investigating a data exfiltration incident. The analyst has identified that the attacker is using a combination of DNS tunneling and HTTPS to exfiltrate data. The analyst needs to recommend a solution to detect and block this activity. The organization has a firewall that can inspect DNS traffic, but it cannot decrypt HTTPS traffic. Which solution would be most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.