Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 1Objective 3

1.3 Describe Security Terms 200-201 Practice Questions (Page 10)

Part of the 1.0 Security Concepts domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)

51questions here
11free pages
9concepts
20%of the exam

Questions 46–50

  1. 46expert · hard

    A security operations center (SOC) monitors a web server's request rate. The normal baseline is 100 requests per minute with a standard deviation of 10. The SOC uses a sliding window anomaly detection algorithm with a window size of 5 minutes and alerts when the average request rate in the window exceeds 120 requests per minute. At 14:00, a distributed denial-of-service (DDoS) attack begins, causing the request rate to jump to 300 requests per minute and remain constant. The SOC wants to minimize false positives while detecting the attack as quickly as possible. Which configuration change would detect the attack faster without significantly increasing false positives?

    Select an answer first
  2. 47application · medium

    A security engineer is analyzing a custom binary that is suspected of containing a backdoor. The engineer needs to understand the binary's control flow and identify the specific function that handles authentication bypass. Which reverse engineering technique is most appropriate for this task?

    Select an answer first
  3. 48expert · hard

    A large e-commerce company is transitioning to a DevSecOps model. The security team wants to integrate security into the CI/CD pipeline without slowing down the release process. The company currently releases updates twice a week. The security team has proposed the following measures: (1) automated static application security testing (SAST) in the build stage, (2) dynamic application security testing (DAST) in the staging environment, and (3) a manual security review before each production release. The development team is concerned that the manual review will cause delays. Which approach best aligns with DevSecOps while addressing the development team's concern?

    Select an answer first
  4. 49expert · hard

    A malware analyst is analyzing a sample that appears to be a dropper for a second-stage payload. The analyst has limited time and needs to quickly determine the C2 infrastructure and the payload's capabilities. The sample is obfuscated and uses a custom packer. Which approach is most time-efficient?

    Select an answer first
  5. 50application · medium

    A malware analyst receives a suspicious executable that was found on a compromised workstation. The analyst needs to determine the malware's command-and-control (C2) server address and the specific system commands it executes. Which combination of analysis methods would be most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.