Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 4Objective 7

4.7 Identify Key Elements in an Intrusion from a Given PCAP File 200-201 Practice Questions (Page 1)

Part of the 4.0 Network Intrusion Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)

41questions here
9free pages
7concepts
20%of the exam

Questions 1–5

  1. 1application · medium

    In a PCAP, an analyst sees a packet with source IP 192.168.1.100, destination IP 8.8.8.8, source port 50000, and destination port 53. The payload contains a DNS query for 'malware.example.com'. What is the destination IP address of this packet?

    Select an answer first
  2. 2application · medium

    A security analyst is reviewing a PCAP from an internal host that contacted an external server. The packet shows an IP header with protocol 17, a UDP header with source port 5353 and destination port 5353, and a payload containing the string '_http._tcp.local'. Which service discovery mechanism is being used?

    Select an answer first
  3. 3application · medium

    A PCAP file contains a packet that starts with a 14-byte Ethernet header, followed by a 20-byte IPv4 header, followed by a TCP header. The analyst needs to find the source port. Where should they look?

    Select an answer first
  4. 4application · medium

    A PCAP shows a TCP connection from 10.0.0.5 to 192.0.2.20. The first packet has source port 49152 and destination port 22. The analyst needs to determine which port the client will use for subsequent packets in the same connection. What should the analyst expect?

    Select an answer first
  5. 5expert · hard

    An analyst is reviewing a PCAP from a compromised host. The PCAP shows a TCP stream from 10.0.0.5 to 203.0.113.7 on destination port 4444. The payload contains a series of commands including 'whoami', 'ls', and 'cat /etc/passwd'. The stream then shows a file transfer containing the string 'MZ' at the start. What is the most likely conclusion?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.