
CiscoCertified CyberOps Associate
Domain 4Objective 7
4.7 Identify Key Elements in an Intrusion from a Given PCAP File 200-201 Practice Questions (Page 6)
Part of the 4.0 Network Intrusion Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
7concepts
20%of the exam
Questions 26–30
- 26
In a TCP segment, which header field indicates the destination port number?
Select an answer first - 27
A PCAP shows a TCP packet with source IP 10.0.0.5, destination IP 192.0.2.1, source port 12345, and destination port 3389. The analyst needs to identify the service that the client is trying to access. Which field should be used?
Select an answer first - 28
What is the purpose of inspecting the payload of packets in a PCAP file during intrusion analysis?
Select an answer first - 29
What is the basic structure of a PCAP file?
Select an answer first - 30
A PCAP shows a UDP packet with source port 5353 and destination port 5353. The payload contains a DNS-SD query for '_http._tcp.local'. Which destination port should the analyst report as the service being queried?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.