Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 2Objective 3

2.3 Describe the Impact of These Technologies on Data Visibility 200-201 Practice Questions (Page 3)

Part of the 2.0 Security Monitoring domain, which accounts for 25% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)

45questions here
9free pages
8concepts
25%of the exam

Questions 11–15

  1. 11expert · hard

    A security team is planning to implement TLS inspection for all outbound HTTPS traffic. The team has a compliance requirement to inspect all traffic for malware, but also a privacy requirement to protect employee personal data. The team is considering using a TLS-intercepting proxy. Which approach balances the need for visibility with the privacy requirement?

    Select an answer first
  2. 12foundation · easy

    How does encapsulation affect the ability of a network monitoring tool to identify the application protocol being used?

    Select an answer first
  3. 13foundation · easy

    A security analyst is trying to correlate a user's session across multiple servers in a load-balanced environment. Why is this difficult?

    Select an answer first
  4. 14application · medium

    A security analyst is monitoring a web application that is behind a load balancer. The load balancer is configured with sticky sessions and performs SNAT. The analyst is correlating web server logs with network flows to investigate a brute-force attack. What challenge does the load balancer introduce to this investigation?

    Select an answer first
  5. 15expert · hard

    A security analyst is investigating a series of failed login attempts against an internal application. The application is behind a load balancer that performs SNAT, and the firewall between the internet and the load balancer performs PAT. The analyst has access to the application logs, which show the source IP as the load balancer's IP, and the firewall logs, which show the translated source IP and port. The analyst also has NetFlow data from the router before the firewall. Which combination of data sources would allow the analyst to identify the original client IP for a specific failed login?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.