Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 2Objective 4

2.4 Describe the Uses of These Data Types in Security Monitoring 200-201 Practice Questions (Page 5)

Part of the 2.0 Security Monitoring domain, which accounts for 25% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)

28questions here
6free pages
6concepts
25%of the exam

Questions 21–25

  1. 21application · medium

    A SOC analyst receives a large number of alerts every day, many of which are false positives. The analyst wants to reduce the noise by correlating alerts with network flow data to see if the source IP actually communicated with the destination IP. Which data type should the analyst use to verify the alert's validity?

    Select an answer first
  2. 22foundation · easy

    A security analyst wants to establish a baseline of normal network traffic by reviewing aggregated metrics such as packet counts and byte counts over time. Which data type would be most useful for this purpose?

    Select an answer first
  3. 23application · medium

    A security operations center (SOC) wants to establish a baseline of normal network traffic for a new office location. They have been collecting NetFlow data for two weeks and want to identify what is 'normal' so they can tune their alerting. Which data type should they use to build this baseline?

    Select an answer first
  4. 24application · medium

    A security analyst notices a sudden spike in traffic from a single workstation to many external IP addresses on port 443. The team has no full packet capture enabled, but they do have NetFlow and IDS alerts. Which data source would best help the analyst quickly determine whether this is a normal pattern or a potential command-and-control beacon?

    Select an answer first
  5. 25application · medium

    A security operations center (SOC) analyst needs to identify which internal hosts are communicating with a known malicious external IP address over the past 24 hours. The analyst does not need to see the content of the communications, only the source and destination IPs, ports, and protocol. Which data source is most appropriate for this task?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.