Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 3Objective 1

3.1 Describe the Functionality of These Endpoint Technologies in Regard to Security Monitoring Utilizing Rules, Signatures, and Predictive AI 200-201 Practice Questions (Page 6)

Part of the 3.0 Host-Based Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
8concepts
20%of the exam

Questions 26–30

  1. 26foundation · easy

    Which type of data would a host-based intrusion detection system (HIDS) typically analyze to detect suspicious activity?

    Select an answer first
  2. 27application · medium

    An organization's antimalware solution is configured to use signature-based detection. A user downloads a file that is a known variant of a Trojan, but the antimalware does not detect it. Which is the most likely reason for the missed detection?

    Select an answer first
  3. 28application · medium

    A workstation is infected with malware that attempts to communicate with an external command-and-control server on TCP port 4444. The security team wants to stop this communication without disrupting the user's ability to browse the web on port 443. Which host-based firewall configuration is most appropriate?

    Select an answer first
  4. 29expert · hard

    A security team is evaluating endpoint protection for a fleet of servers that run a legacy application. The application is known to perform unusual but legitimate actions, such as writing to system directories and spawning child processes. The team wants to detect malware without disrupting the application. Which detection strategy best balances detection capability and operational stability?

    Select an answer first
  5. 30application · medium

    A company deploys a host-based firewall on all employee laptops. A user reports that a legitimate internal application can no longer connect to its server on TCP port 8443. The firewall is configured with a default-deny policy. Which rule should the administrator add to restore connectivity while maintaining security?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.