
CiscoCertified CyberOps Associate
Domain 2Objective 5
2.5 Describe Network Attacks, Such as Protocol-Based, Denial of Service, Distributed Denial of Service, and Man-In-The-Middle 200-201 Practice Questions (Page 5)
Part of the 2.0 Security Monitoring domain, which accounts for 25% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
4concepts
25%of the exam
Questions 21–23
- 21
A company's web server is experiencing intermittent outages. The security team finds that the server is receiving a high volume of TCP SYN packets from a single IP address, but the server's SYN queue is filling up and legitimate connections are being dropped. Which type of attack is this, and what is the most effective mitigation?
Select an answer first - 22
A company's e-commerce site is hit by a DDoS attack that uses a botnet of thousands of compromised IoT devices to send HTTP requests to the web server, overwhelming its CPU and memory. Which characteristic distinguishes this attack from a single-source DoS attack?
Select an answer first - 23
A network engineer is troubleshooting a server that becomes unresponsive every day at the same time. The server logs show a large number of incomplete TCP handshakes from a single IP address. The engineer suspects a SYN flood. Which mitigation would be most effective in preventing the exhaustion of the server's connection table?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to 200-201
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.