
CiscoCertified CyberOps Associate
Domain 1Objective 9
1.9 Identify Potential Data Loss from Traffic Profiles 200-201 Practice Questions (Page 3)
Part of the 1.0 Security Concepts domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
5concepts
20%of the exam
Questions 11–15
- 11
A company's security team has a baseline that shows the marketing department typically uploads a total of 200 MB per day to a cloud file-sharing service. Today, a single marketing user uploaded 1.5 GB in one hour to the same service. The user's manager confirms the user was working on a large video project. What should the analyst do next?
Select an answer first - 12
What is the primary purpose of traffic profiling in network security monitoring?
Select an answer first - 13
What does correlating traffic anomalies with data loss events help an analyst do?
Select an answer first - 14
Which traffic pattern is most indicative of potential data exfiltration?
Select an answer first - 15
A security analyst is reviewing network traffic and notices that a user is sending large files to a personal webmail account via HTTPS. The organization's policy prohibits sending sensitive data to personal email. Which data loss vector is being used?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.