
CiscoCertified CyberOps Associate
Domain 3Objective 3
3.3 Describe the Role of Attribution in an Investigation 200-201 Practice Questions (Page 6)
Part of the 3.0 Host-Based Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
5concepts
20%of the exam
Questions 26–30
- 26
During an investigation, an analyst identifies a series of IOCs that include a specific malware family, a command-and-control domain, and a unique encryption routine. The analyst wants to use these to infer the likely threat actor. Which approach is most effective?
Select an answer first - 27
What is an indicator of compromise (IOC)?
Select an answer first - 28
A large enterprise has suffered a data breach. The incident response team has identified several IOCs, including a unique malware hash and a C2 domain. The team also has a list of affected assets. However, the CEO wants to know who is behind the attack. The team has limited time and budget. What is the most appropriate approach to attribution?
Select an answer first - 29
Which of the following is an example of an indicator of attack (IOA)?
Select an answer first - 30
A forensic analyst is collecting evidence from a compromised server. The analyst takes a forensic image of the hard drive and then begins analyzing it. Later, the analyst needs to present the evidence in court. What must the analyst have maintained to ensure the evidence is admissible?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.