Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 3Objective 1

3.1 Describe the Functionality of These Endpoint Technologies in Regard to Security Monitoring Utilizing Rules, Signatures, and Predictive AI 200-201 Practice Questions (Page 9)

Part of the 3.0 Host-Based Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
8concepts
20%of the exam

Questions 41–45

  1. 41expert · hard

    An organization has a HIDS deployed on all endpoints. The HIDS uses rules to monitor for new services and signature-based detection for known malware. Recently, a legitimate software update installed a new service, triggering a high-priority alert. The analyst wants to prevent similar false positives in the future without losing visibility into unauthorized service installations. Which action is most appropriate?

    Select an answer first
  2. 42application · medium

    A security analyst is evaluating a host-based intrusion detection system (HIDS) for a network of Windows servers. The primary requirement is to detect when a critical system file is modified or when a new service is installed, which could indicate compromise. The analyst also wants to detect known malware that might be dropped onto the servers. Which combination of HIDS capabilities is most appropriate?

    Select an answer first
  3. 43expert · hard

    A company's security policy requires that endpoints block all inbound traffic by default, except for remote desktop (RDP) access from a specific admin subnet. The host-based firewall is configured accordingly. A new vulnerability is discovered in the RDP service, and the security team wants to reduce risk without losing remote management capability. Which action best balances security and operational needs?

    Select an answer first
  4. 44application · medium

    A security analyst notices that a known malware variant, previously identified by a specific SHA-256 hash, is being blocked by the endpoint protection platform. However, the analyst is concerned that a slightly modified version of the same malware, with a different hash, might evade detection. Which detection mechanism should the analyst verify is enabled to catch the modified variant?

    Select an answer first
  5. 45application · medium

    A security operations center wants to deploy an endpoint protection solution that can identify never-before-seen malware by learning from millions of endpoint events. The solution should improve over time as more data is collected. Which technology is best suited for this requirement?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.