
CiscoCertified CyberOps Associate
Domain 1Objective 9
1.9 Identify Potential Data Loss from Traffic Profiles 200-201 Practice Questions (Page 2)
Part of the 1.0 Security Concepts domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
5concepts
20%of the exam
Questions 6–10
- 6
Which statement best describes how traffic profiling distinguishes abnormal from normal network behavior?
Select an answer first - 7
A security analyst is tasked with identifying potential data loss from traffic profiles. The analyst has access to NetFlow data and a baseline of normal network behavior. Which approach would be most effective in detecting a data exfiltration attempt that uses a legitimate cloud storage service?
Select an answer first - 8
A security analyst is investigating a potential data loss incident. The analyst sees a large outbound transfer to an external IP that is not on the approved list. The transfer occurred at 2:00 AM, and the user associated with the workstation was on vacation. Which additional data would most help confirm the data loss event?
Select an answer first - 9
A security analyst notices that a workstation is sending a large amount of data to an external IP address on port 53 (DNS) during off-hours. The data is being sent in a continuous stream rather than as typical DNS queries. Which data loss vector is most likely being used?
Select an answer first - 10
What is the first step in analyzing traffic profiles for anomalies?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.