
CiscoCertified CyberOps Associate
Domain 1Objective 9
1.9 Identify Potential Data Loss from Traffic Profiles 200-201 Practice Questions (Page 5)
Part of the 1.0 Security Concepts domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
5concepts
20%of the exam
Questions 21–23
- 21
A security analyst at a financial firm notices that a finance workstation has been sending large volumes of data to a cloud storage service during off-hours over the past week. The baseline shows that this workstation normally sends less than 50 MB per day to any external service. Which action should the analyst take first to confirm whether this is a data loss event?
Select an answer first - 22
A security analyst is investigating a potential data breach. The analyst notices that a server with sensitive customer data has been sending small, frequent DNS queries to a domain that is not on the organization's approved list. The queries contain encoded data. What should the analyst do to confirm whether data loss is occurring?
Select an answer first - 23
A security analyst observes a spike in outbound HTTPS traffic from a database server to a file-sharing website during non-business hours. The server normally has no outbound traffic. The analyst also sees that the server's local logs show a large number of failed login attempts earlier that day. Which conclusion is most supported by correlating these observations?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to 200-201
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.