
CiscoCertified CyberOps Associate
Domain 2Objective 11
2.11 Identify the Certificate Components in a Given Scenario 200-201 Practice Questions (Page 3)
Part of the 2.0 Security Monitoring domain, which accounts for 25% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
6concepts
25%of the exam
Questions 11–15
- 11
A security analyst needs to export a certificate along with its private key to migrate a web server to a new host. Which PKCS standard is designed for securely storing and transporting a private key and certificate together?
Select an answer first - 12
A security analyst is investigating a certificate validation failure for a public website. The browser shows the certificate is valid and trusted, but the connection is still blocked with a warning about the certificate being revoked. The analyst checks the certificate and sees that it does not contain a CRL Distribution Point (CDP) extension. What is the most likely reason for the revocation warning?
Select an answer first - 13
A security team is configuring TLS for a high-security web service. They must support legacy clients that only support TLS 1.0 and RSA key exchange, but the security policy requires forward secrecy for all connections. The team is evaluating options. Which approach best satisfies both constraints?
Select an answer first - 14
A company runs an internal web application that uses a certificate issued by an internal root CA. The root CA certificate is distributed to all clients via Group Policy. Recently, the root CA's private key was compromised, and the security team needs to reissue all certificates. The team creates a new root CA and issues a new certificate for the web server. However, clients that have not yet received the new root CA certificate are failing to connect. The team cannot immediately update all clients. What is the most effective solution to maintain trust for existing clients while transitioning to the new root CA?
Select an answer first - 15
A security analyst is reviewing a TLS handshake and sees that the client and server negotiate a cipher suite that uses RSA for key exchange. The analyst is concerned about the risk of a man-in-the-middle attack if the server's private key is compromised. Which mitigation would be most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.