
CiscoCertified CyberOps Associate
Domain 2Objective 4
2.4 Describe the Uses of These Data Types in Security Monitoring 200-201 Practice Questions (Page 3)
Part of the 2.0 Security Monitoring domain, which accounts for 25% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
6concepts
25%of the exam
Questions 11–15
- 11
A SOC analyst is trying to detect a slow and low data exfiltration attack that involves small amounts of data being sent over long periods. The analyst has access to session data, statistical data, and alert data. Which data source would be most effective for detecting this type of attack?
Select an answer first - 12
A network security team is planning to implement a new monitoring solution. The team has a limited budget and needs to choose between storing full packet capture for one week or session data for one year. The team's primary goal is to detect anomalies and perform historical analysis of network behavior. Which choice best meets the team's needs?
Select an answer first - 13
Which characteristic is unique to full packet capture compared to other network monitoring data types?
Select an answer first - 14
A SOC analyst wants to establish a baseline of normal network traffic for a critical server to detect anomalies. The analyst needs to know the average packet rate, byte count, and number of connections per hour over the past month. Which data source is best suited for this baseline analysis?
Select an answer first - 15
A SOC manager wants to detect a distributed denial-of-service (DDoS) attack early by monitoring for unusual increases in traffic volume. The team has access to NetFlow data and wants to set up an alert that triggers when traffic exceeds a threshold. Which data type should be used to define the threshold and detect the anomaly?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.