Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 2Objective 11

2.11 Identify the Certificate Components in a Given Scenario 200-201 Practice Questions (Page 5)

Part of the 2.0 Security Monitoring domain, which accounts for 25% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
6concepts
25%of the exam

Questions 21–25

  1. 21expert · hard

    A security analyst is reviewing a TLS handshake and sees that the client and server negotiated TLS 1.2 with the cipher suite TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256. The analyst notices that the server's certificate is signed with SHA-1. What is the most significant security concern?

    Select an answer first
  2. 22application · medium

    A security analyst is examining a certificate and sees the following fields: Subject: CN=mail.example.com, Issuer: CN=Example Root CA, Validity: Not Before Jan 1 2024, Not After Jan 1 2025, Public Key: RSA 2048, Extensions: Subject Alternative Name (SAN) includes mail.example.com and smtp.example.com. The analyst wants to confirm that the certificate can be used for both mail and SMTP services. Which field is most relevant for this purpose?

    Select an answer first
  3. 23expert · hard

    A security engineer is designing a TLS 1.2 configuration for a high-traffic e-commerce platform. The platform must support legacy clients that only support RSA key exchange, but the security policy requires forward secrecy for all sessions. The engineer cannot upgrade the legacy clients. What is the best approach to balance security and compatibility?

    Select an answer first
  4. 24expert · medium

    A security analyst is troubleshooting a TLS 1.2 connection that fails only for clients on the corporate network, while external clients can connect successfully. The server presents a certificate issued by an internal CA. The internal CA certificate is not in the trust store of the corporate clients, but it is in the trust store of external clients. What is the most likely cause?

    Select an answer first
  5. 25application · medium

    A security analyst is comparing two TLS configurations: one uses RSA key exchange and the other uses ECDHE. The analyst is concerned about the impact of a server private key compromise on past sessions. Which statement accurately describes the difference?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.