Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 2Objective 10

2.10 Describe the Impact of Certificates on Security (includes PKI, Public/private Crossing the Network, Asymmetric/symmetric) 200-201 Practice Questions (Page 6)

Part of the 2.0 Security Monitoring domain, which accounts for 25% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)

36questions here
8free pages
5concepts
25%of the exam

Questions 26–30

  1. 26expert · hard

    A security analyst is investigating a phishing attack where users were tricked into visiting a fake website that presented a valid-looking certificate. The certificate was issued by a legitimate public CA, but it was for a different domain name. The analyst finds that the users ignored the browser warning. What is the most likely reason the certificate was issued for the wrong domain, and what is the best mitigation?

    Select an answer first
  2. 27application · medium

    A security analyst is investigating a man-in-the-middle attack on a corporate web application. The analyst finds that users are seeing a certificate warning in their browsers, but some users proceed anyway. The attacker is presenting a certificate that was issued by a CA that is not in the browsers' trust store. What is the primary security control that failed, allowing the attack to succeed for users who clicked through the warning?

    Select an answer first
  3. 28expert · hard

    A company is planning to migrate from a public CA to an internal CA for its external-facing web applications. The security team is concerned about the impact on customers. Which consideration is most important to address before the migration?

    Select an answer first
  4. 29application · medium

    A security analyst notices that a server's certificate has been revoked because the private key was compromised. The analyst must ensure that clients do not accept the compromised certificate. Which mechanism should the analyst verify is in place?

    Select an answer first
  5. 30application · medium

    A security engineer is designing a system where a server must prove its identity to clients without exposing its private key. Which action does the server perform during the TLS handshake to prove possession of the private key?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.