
CiscoCertified CyberOps Associate
Domain 3Objective 3
3.3 Describe the Role of Attribution in an Investigation 200-201 Practice Questions (Page 1)
Part of the 3.0 Host-Based Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
5concepts
20%of the exam
Questions 1–5
- 1
What is the primary purpose of threat actor profiling in an investigation?
Select an answer first - 2
During an investigation, an analyst finds a malicious file on a compromised host. The analyst wants to determine if this file is associated with a known threat actor. What is the most effective way to use this IOC for attribution?
Select an answer first - 3
During an investigation, an analyst discovers that a compromised workstation was used to pivot to a database server. The analyst needs to understand the full scope of the attack for attribution. Which step is most important?
Select an answer first - 4
An incident response team is analyzing a breach where the attacker used a zero-day exploit, custom malware, and a unique command-and-control protocol. The team wants to attribute the attack to a specific threat actor. Which information would be most useful?
Select an answer first - 5
A security analyst is investigating a malware infection. The analyst finds a file hash, a registry key, and a network connection to a known malicious domain. The analyst wants to use these to support attribution. Which action is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.