Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 2Objective 3

2.3 Describe the Impact of These Technologies on Data Visibility 200-201 Practice Questions (Page 4)

Part of the 2.0 Security Monitoring domain, which accounts for 25% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)

45questions here
9free pages
8concepts
25%of the exam

Questions 16–20

  1. 16application · medium

    A security analyst is investigating a data exfiltration incident. The logs show that a workstation established a connection to a known Tor relay. The analyst wants to determine what data was sent. The traffic between the workstation and the Tor network is encrypted and routed through multiple relays. What is the primary limitation the analyst faces in seeing the exfiltrated data?

    Select an answer first
  2. 17expert · hard

    A security analyst is tasked with detecting malware command-and-control (C2) traffic that is known to use DNS tunneling. The analyst has visibility into the corporate DNS server logs and the network traffic at the internet egress. The C2 traffic is encapsulated in DNS queries and responses. The analyst also knows that the C2 traffic is encrypted with a custom algorithm. Which approach would provide the best visibility into the C2 traffic?

    Select an answer first
  3. 18application · medium

    A network engineer is troubleshooting why a network analyzer is not showing the expected HTTP traffic between two hosts. The traffic is encapsulated in a VXLAN tunnel. The analyzer is connected to a SPAN port on the same switch as the source host. What is the most likely reason the analyzer does not see the HTTP payload?

    Select an answer first
  4. 19application · medium

    A security analyst is monitoring traffic on a network that uses GRE tunnels between remote sites. The analyst notices that the IDS is not generating alerts for malware traffic that is known to be active on the internal network. The traffic is encapsulated in GRE. What is the most likely reason the IDS is missing the malicious payload?

    Select an answer first
  5. 20application · medium

    A security team is deploying a new intrusion prevention system (IPS) inline on the network. The network carries both encrypted and unencrypted traffic. The team wants to ensure the IPS can inspect all traffic for threats. What should the team do to achieve visibility into the encrypted traffic?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.