
CiscoCertified CyberOps Associate
Domain 1Objective 3
1.3 Describe Security Terms 200-201 Practice Questions (Page 3)
Part of the 1.0 Security Concepts domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
9concepts
20%of the exam
Questions 11–15
- 11
A SOC receives an alert for a potential data exfiltration via DNS tunneling. The incident response run book specifies steps to isolate the host, capture a memory dump, and review DNS logs. The SOC wants to ensure these steps are executed consistently and quickly. Which approach best achieves this?
Select an answer first - 12
A SOC manager has a small team and limited budget. The team receives threat intelligence about a new fileless attack that uses PowerShell to inject code into running processes. The manager wants to proactively identify if any hosts are compromised, but the EDR does not log PowerShell script blocks. The team has access to Windows Event Logs (including Sysmon) and network flow data. Which approach is the most effective given these constraints?
Select an answer first - 13
What is the primary purpose of malware analysis?
Select an answer first - 14
A regional bank has been hit by a series of targeted phishing emails that use the bank's own branding and reference recent local events. The emails are sent only to employees in the finance department, and the payload is a macro-enabled document that downloads a known remote access trojan. The bank's threat intelligence team has identified the attacker as a financially motivated group operating from a neighboring country. The CISO wants to prioritize defenses against this specific threat. Which combination of actions best aligns with the threat intelligence and threat modeling concepts?
Select an answer first - 15
A financial services company is developing a new mobile banking application. The security team is conducting a threat model and has identified that the application will store sensitive user data on the device. The team is considering two mitigations: encrypting the data at rest and implementing certificate pinning to prevent man-in-the-middle attacks. The development team is concerned about the performance impact of encryption and the operational overhead of certificate pinning. The company's risk appetite is low, and it must comply with data protection regulations. Which approach best balances security and development constraints?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.