Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 3Objective 1

3.1 Describe the Functionality of These Endpoint Technologies in Regard to Security Monitoring Utilizing Rules, Signatures, and Predictive AI 200-201 Practice Questions (Page 1)

Part of the 3.0 Host-Based Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
8concepts
20%of the exam

Questions 1–5

  1. 1expert · hard

    A HIDS is configured with a rule that triggers an alert when the number of failed login attempts exceeds five within ten minutes. An attacker is using a slow brute-force attack, making only three attempts every ten minutes, and the HIDS is not alerting. The analyst wants to detect this slow attack without increasing false positives from legitimate users who occasionally mistype passwords. Which adjustment is most effective?

    Select an answer first
  2. 2foundation · easy

    A security analyst is reviewing the capabilities of a host-based intrusion detection system (HIDS) for deployment on critical servers. Which statement accurately describes the primary function of a HIDS?

    Select an answer first
  3. 3application · medium

    A HIDS is configured to alert when a specific system file is modified. The file is changed during a legitimate software update, and the HIDS generates an alert. Which type of detection is responsible for this alert?

    Select an answer first
  4. 4application · medium

    A user's laptop is infected with malware that attempts to communicate with a command-and-control server over an unusual port. The host-based firewall is configured with a default-allow outbound policy. Which configuration change would best prevent this communication while minimizing disruption?

    Select an answer first
  5. 5application · medium

    An endpoint protection product is configured to monitor running processes. A new piece of software attempts to encrypt a large number of user documents and then delete the originals. No signature exists for this software. Which detection capability is most likely to flag this behavior?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.