Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 2Objective 3

2.3 Describe the Impact of These Technologies on Data Visibility 200-201 Practice Questions (Page 6)

Part of the 2.0 Security Monitoring domain, which accounts for 25% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)

45questions here
9free pages
8concepts
25%of the exam

Questions 26–30

  1. 26application · medium

    A security analyst is reviewing NetFlow records to identify the source IP of a malicious scan. The traffic passed through a firewall that performs PAT (Port Address Translation) and also has an ACL that permits only HTTP and HTTPS traffic. The analyst sees many flows from the firewall's public IP to various internal servers on port 443. What is the primary challenge in correlating these flows to the original internal host?

    Select an answer first
  2. 27application · medium

    A security analyst is monitoring network traffic for signs of data exfiltration. The analyst notices a workstation that is sending a steady stream of small packets to a known Tor relay. The analyst wants to determine what data is being sent. What is the primary obstacle to seeing the actual data being exfiltrated?

    Select an answer first
  3. 28application · medium

    A security operations center (SOC) uses an intrusion detection system (IDS) to monitor traffic to a web application. The web application recently enabled TLS for all client connections. The SOC analysts notice that the IDS is no longer generating alerts for SQL injection attempts that were previously detected. What is the most likely reason for the loss of visibility?

    Select an answer first
  4. 29expert · hard

    A security analyst is investigating a potential data exfiltration incident involving a peer-to-peer (P2P) application. The analyst has network flow data showing many connections to various IPs on random ports. The P2P application uses encryption and obfuscation. The analyst also has endpoint logs from the user's workstation. Which approach would be most effective in determining whether data was exfiltrated?

    Select an answer first
  5. 30expert · hard

    A security analyst is investigating a user who is suspected of using Tor to access illegal content. The analyst has access to the corporate proxy logs, which show that the user's workstation made a connection to a Tor relay on port 9001. The analyst also has network flow data from the firewall. The user's traffic to the Tor network is encrypted. What is the most effective way to determine what the user accessed while using Tor?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.