Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 2Objective 3

2.3 Describe the Impact of These Technologies on Data Visibility 200-201 Practice Questions (Page 5)

Part of the 2.0 Security Monitoring domain, which accounts for 25% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)

45questions here
9free pages
8concepts
25%of the exam

Questions 21–25

  1. 21application · medium

    A security analyst is examining packet captures of traffic between two internal hosts. The analyst notices that the packets have an additional header that is not typical for the application protocol being used. The analyst suspects that the traffic is encapsulated. What is the primary impact of this encapsulation on the analyst's ability to monitor the traffic?

    Select an answer first
  2. 22expert · hard

    A security analyst is configuring a network tap to monitor traffic between two internal subnets. The network team has applied an ACL on the core switch that permits only HTTP and HTTPS traffic between the subnets. The analyst wants to see all traffic, including ICMP and other protocols, for security monitoring. What is the most effective way to ensure the monitoring tool sees all traffic?

    Select an answer first
  3. 23application · medium

    A network analyst is using a protocol analyzer to troubleshoot a slow application. The application traffic is encapsulated in a proprietary tunneling protocol that adds a custom header. The analyzer is not decoding the inner protocol. What is the most likely impact on the analyst's ability to see the application's performance issues?

    Select an answer first
  4. 24expert · hard

    A security analyst is investigating a data breach. The analyst has NetFlow records from the perimeter firewall. The records show a large amount of data being transferred from an internal host to a public IP address. The analyst suspects the data was exfiltrated through a VPN tunnel. The NetFlow records show the VPN gateway's IP as the destination, not the actual external server. What is the most effective way to determine the actual destination of the exfiltrated data?

    Select an answer first
  5. 25application · medium

    A security analyst is monitoring a network where employees are using a peer-to-peer (P2P) file-sharing application. The analyst is trying to identify which internal hosts are communicating with known malicious peers. What is the main challenge the analyst faces when correlating P2P traffic to specific hosts?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.