
CiscoCertified CyberOps Associate
Domain 1Objective 3
1.3 Describe Security Terms 200-201 Practice Questions (Page 2)
Part of the 1.0 Security Concepts domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
9concepts
20%of the exam
Questions 6–10
- 6
A security analyst is reviewing a series of attacks against a government defense contractor. The attacks involve sophisticated spear-phishing emails with zero-day exploits and are believed to be sponsored by a nation-state. The attacker's goal appears to be stealing classified project information. Which threat actor type best matches this scenario?
Select an answer first - 7
A SOC team spends significant time manually responding to repeated phishing alerts. Each alert requires the analyst to check the email headers, block the sender, and notify the affected user. The SOC manager wants to reduce response time and ensure consistency. Which approach best addresses this need?
Select an answer first - 8
A network monitoring system tracks the number of failed login attempts per minute. The security team wants to detect a brute-force attack that gradually increases the attempt rate over several hours. Which anomaly detection approach would best identify this slow-building pattern?
Select an answer first - 9
A company is adopting a DevOps culture and wants to integrate security into its continuous integration/continuous deployment (CI/CD) pipeline. The security team wants to ensure that vulnerabilities are identified and addressed as early as possible without slowing down development. Which approach best aligns with the DevSecOps philosophy?
Select an answer first - 10
A security operations team receives a threat intelligence report that a specific advanced persistent threat (APT) group is targeting organizations in the same industry. The report includes indicators of compromise (IOCs) such as IP addresses, domain names, and file hashes. The team wants to proactively search for any signs of this APT in their environment. Which action is the most aligned with using threat intelligence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.