
CiscoCertified CyberOps Associate
Domain 2Objective 3
2.3 Describe the Impact of These Technologies on Data Visibility 200-201 Practice Questions (Page 1)
Part of the 2.0 Security Monitoring domain, which accounts for 25% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
8concepts
25%of the exam
Questions 1–5
- 1
In a network that uses Port Address Translation (PAT), how does PAT affect the visibility of internal host connections in monitored traffic?
Select an answer first - 2
A security analyst is configuring a network-based intrusion detection system (IDS) to monitor traffic between two internal servers. The servers communicate using TLS encryption. The analyst wants to detect a specific application-layer attack that is known to be sent in the clear. What is the most effective approach to gain visibility into the application-layer payload?
Select an answer first - 3
A security analyst is troubleshooting why a network-based intrusion detection system (IDS) is not seeing HTTP requests from a specific user subnet to a web server. The network team recently implemented an access control list (ACL) on the router between the user subnet and the server, and also introduced a load balancer in front of the web server. The IDS is connected to a SPAN port on the switch that connects to the web server. Which two factors most directly explain the missing visibility?
Select an answer first - 4
A security analyst is monitoring traffic for a remote user who connects to the corporate network via a VPN. The analyst wants to inspect the traffic for malware signatures. The VPN traffic is encapsulated in IPsec. What is the primary limitation the analyst faces when trying to inspect the VPN traffic?
Select an answer first - 5
A security analyst is monitoring traffic on a network that uses IPsec VPN tunnels for remote access. The analyst notices that the IDS is not detecting malware that is known to be spreading through the VPN traffic. What is the most likely reason for the lack of detection?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.