Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 2Objective 11

2.11 Identify the Certificate Components in a Given Scenario 200-201 Practice Questions (Page 4)

Part of the 2.0 Security Monitoring domain, which accounts for 25% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
6concepts
25%of the exam

Questions 16–20

  1. 16application · medium

    A security analyst needs to provide a third-party vendor with a copy of a public certificate for integration testing. The vendor does not need the private key. Which file format should the analyst provide?

    Select an answer first
  2. 17application · medium

    A CyberOps analyst is investigating a certificate validation failure for an internal web application. The certificate's subject is 'CN=web.internal.corp' and the issuer is 'CN=Corp Internal CA'. The browser reports that the certificate is not trusted. The analyst verifies that the certificate is within its validity period and that the hostname matches. What is the most likely cause of the failure?

    Select an answer first
  3. 18application · medium

    A security administrator receives a file with a .p7b extension from a third-party vendor. The file is intended to be used to trust the vendor's internal CA. What does this file contain?

    Select an answer first
  4. 19application · medium

    A network administrator is configuring a web server to support TLS 1.2. The administrator selects the cipher suite TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256. During the TLS handshake, which component of this cipher suite is used to authenticate the server to the client?

    Select an answer first
  5. 20application · medium

    A security analyst is reviewing a TLS 1.3 handshake capture and notices that the ClientHello offers only cipher suites that use ephemeral Diffie-Hellman for key exchange. The analyst wants to ensure that the session keys cannot be recovered even if the server's long-term private key is later compromised. Which property of the negotiated key exchange provides this protection?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.