
CiscoCertified CyberOps Associate
Domain 2Objective 11
2.11 Identify the Certificate Components in a Given Scenario 200-201 Practice Questions (Page 2)
Part of the 2.0 Security Monitoring domain, which accounts for 25% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
6concepts
25%of the exam
Questions 6–10
- 6
A security analyst is troubleshooting a certificate validation failure for an internal service. The certificate is issued by an intermediate CA, and the root CA is in the client's trust store. The server sends only its leaf certificate during the handshake. The analyst has access to the intermediate certificate file. What is the most efficient way to resolve the issue?
Select an answer first - 7
A security analyst is validating a server certificate chain. The root CA certificate is in the client's trust store. The intermediate CA certificate is not in the trust store, but the server sends it during the handshake. What is the result of the validation?
Select an answer first - 8
A security analyst is investigating a TLS 1.2 connection that failed validation. The server certificate has a valid signature from a trusted root, but the client still rejects it. The analyst checks the certificate and finds that the 'Validity' field shows 'Not Before: 2023-01-01' and 'Not After: 2023-12-31'. The current date is 2024-06-01. What is the most likely reason for the validation failure?
Select an answer first - 9
A security administrator needs to deploy a certificate to a web server that requires the private key to be stored in a hardware security module (HSM). The certificate is currently in a PKCS#12 file. What is the best way to import the certificate into the HSM?
Select an answer first - 10
A security analyst is examining a certificate and sees that the 'Issuer' field is 'CN=Example Root CA' and the 'Subject' field is 'CN=Example Intermediate CA'. The analyst also sees a second certificate where the 'Issuer' is 'CN=Example Intermediate CA' and the 'Subject' is 'CN=web.example.com'. What does this structure represent?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.