Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 2Objective 4

2.4 Describe the Uses of These Data Types in Security Monitoring 200-201 Practice Questions (Page 1)

Part of the 2.0 Security Monitoring domain, which accounts for 25% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)

28questions here
6free pages
6concepts
25%of the exam

Questions 1–5

  1. 1expert · hard

    A security analyst is investigating a lateral movement attack within the network. The analyst has metadata from the authentication system, session data from the firewall, and full packet capture from the internal network. The analyst needs to trace the path of the attacker from one host to another. Which data source would be most useful for this tracing?

    Select an answer first
  2. 2application · medium

    During an incident investigation, an analyst has identified a suspicious file downloaded by a user. The analyst wants to check if this file is known malware by comparing its hash against a threat intelligence feed, without needing to analyze the file's contents. Which data type would provide the necessary information for this comparison?

    Select an answer first
  3. 3expert · hard

    A security analyst is investigating a phishing email that contained a malicious attachment. The analyst has the email metadata, including the sender, recipient, subject, and timestamp. The analyst also has full packet capture of the network traffic and transaction data from the email gateway. The analyst needs to determine if the attachment was downloaded by any user and if so, which user. Which data source is most useful for this determination?

    Select an answer first
  4. 4expert · hard

    A security team is investigating a malware outbreak. They have identified a suspicious file that was downloaded by multiple hosts. The team wants to determine if the file is the same across all hosts and if it matches known malware, without sharing the file content externally. Which combination of data types would best support this investigation?

    Select an answer first
  5. 5application · medium

    A network administrator needs to quickly identify which internal hosts are communicating with a known malicious IP address. The company has NetFlow enabled but does not have full packet capture for all traffic. Which data source should the administrator use to get a list of all internal hosts that have communicated with the malicious IP?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.