Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 3Objective 1

3.1 Describe the Functionality of These Endpoint Technologies in Regard to Security Monitoring Utilizing Rules, Signatures, and Predictive AI 200-201 Practice Questions (Page 8)

Part of the 3.0 Host-Based Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
8concepts
20%of the exam

Questions 36–40

  1. 36expert · hard

    An endpoint protection product uses signature-based detection with a local cache of file hashes. A user downloads a legitimate file that is not in the cache. The product allows the file to run. Later, the file is found to be malware that was not yet known at the time of download. Which detection mechanism would have been most likely to prevent this execution?

    Select an answer first
  2. 37foundation · easy

    In a host-based intrusion detection system (HIDS), what is the primary difference between rule-based and signature-based detection?

    Select an answer first
  3. 38application · medium

    A workstation's host-based firewall is blocking a legitimate application that needs to listen for incoming connections on a high port (e.g., 50000) for a peer-to-peer feature. The firewall uses a default-deny inbound policy. Which configuration change should be made to allow this while minimizing risk?

    Select an answer first
  4. 39expert · hard

    A user reports that a legitimate application cannot connect to the internet after a host-based firewall update. The firewall is configured with a default-deny outbound policy and allows only specific applications. The application is not in the allowlist. Which action should the administrator take to restore connectivity while maintaining the security posture?

    Select an answer first
  5. 40expert · hard

    An organization is considering adding predictive AI to its endpoint security stack. The SOC currently relies on signatures and simple rules. The team is concerned about the AI generating too many false positives and overwhelming analysts. Which implementation approach would best address this concern while still improving detection of novel threats?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.