
CiscoCertified CyberOps Associate
Domain 1Objective 9
1.9 Identify Potential Data Loss from Traffic Profiles 200-201 Practice Questions (Page 1)
Part of the 1.0 Security Concepts domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
5concepts
20%of the exam
Questions 1–5
- 1
Which protocol anomaly could indicate data exfiltration?
Select an answer first - 2
Which technique is used to compare current traffic against a baseline to detect deviations?
Select an answer first - 3
Which action is part of correlating traffic with a potential data loss event?
Select an answer first - 4
Which of the following is a common vector for data loss?
Select an answer first - 5
A security analyst is reviewing traffic logs and notices that a workstation has been sending a large number of HTTP POST requests to a website that hosts a file-sharing service. The requests are occurring outside normal business hours and the payload sizes are unusually large. The workstation belongs to an employee who has no business need to use that service. What does this traffic profile most likely indicate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.