
CiscoCertified CyberOps Associate
Domain 4Objective 7
4.7 Identify Key Elements in an Intrusion from a Given PCAP File 200-201 Practice Questions (Page 3)
Part of the 4.0 Network Intrusion Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
7concepts
20%of the exam
Questions 11–15
- 11
In a PCAP file, which protocol is indicated by the value 1 in the IPv4 Protocol field?
Select an answer first - 12
A PCAP shows a UDP packet with source IP 10.0.0.2, destination IP 10.0.0.255, source port 68, and destination port 67. What is the source port number?
Select an answer first - 13
An analyst is investigating a PCAP and finds a TCP stream from 10.0.0.5 to 203.0.113.7 on port 80. The payload contains 'GET /payload.bin HTTP/1.1' followed by a response with 'Content-Type: application/octet-stream'. The response body begins with 'MZ'. What is the most likely action?
Select an answer first - 14
An analyst is using tcpdump to capture traffic on an interface. The capture file shows a packet with an Ethernet header, an IPv4 header, and a TCP header. The analyst needs to verify that the capture contains the full payload of the TCP segment. What should the analyst check?
Select an answer first - 15
An analyst is examining a PCAP and finds a TCP stream to port 4444. The payload contains the string 'MZ' at the beginning, followed by binary data. What should the analyst conclude about the payload?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.