Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 2Objective 5

2.5 Describe Network Attacks, Such as Protocol-Based, Denial of Service, Distributed Denial of Service, and Man-In-The-Middle 200-201 Practice Questions (Page 4)

Part of the 2.0 Security Monitoring domain, which accounts for 25% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)

23questions here
5free pages
4concepts
25%of the exam

Questions 16–20

  1. 16application · medium

    A network administrator notices that a server is consuming excessive CPU and memory resources. The server logs show a large number of incomplete TCP connections in the SYN-RECEIVED state. The source IP addresses are spoofed and vary widely. Which attack is occurring, and what is the most effective mitigation?

    Select an answer first
  2. 17application · medium

    A company's web server becomes unresponsive during a marketing campaign. The security team finds that the server is receiving a high volume of legitimate-looking HTTP GET requests for the homepage from a single IP address. The requests are coming faster than the server can process them. Which type of attack is this, and what is the most appropriate immediate action?

    Select an answer first
  3. 18application · medium

    A network engineer is reviewing firewall logs and sees a large number of ICMP echo requests with a destination address of 192.168.1.255. The requests are coming from an external source. The engineer suspects a Smurf attack. What is the primary mechanism of a Smurf attack, and what is the best mitigation?

    Select an answer first
  4. 19foundation · easy

    What is the primary goal of a denial-of-service (DoS) attack?

    Select an answer first
  5. 20application · medium

    A security analyst is investigating an incident where a user's web session was hijacked. The attacker was able to predict the session token and inject packets into the TCP stream, allowing them to send commands as the user. Which attack technique is being described?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.