
CiscoCertified CyberOps Associate
Domain 2Objective 11
2.11 Identify the Certificate Components in a Given Scenario 200-201 Practice Questions (Page 6)
Part of the 2.0 Security Monitoring domain, which accounts for 25% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
6concepts
25%of the exam
Questions 26–30
- 26
A security analyst is troubleshooting a client that fails to establish a TLS 1.2 connection to an internal server. The server presents a certificate issued by an intermediate CA. The client's trust store contains the root CA certificate but not the intermediate CA certificate. The server does not send the intermediate certificate during the handshake. What is the most likely cause of the failure?
Select an answer first - 27
Which X.509 certificate field is used to specify the period during which the certificate is considered valid?
Select an answer first - 28
When validating a certificate, what is the role of the root CA's self-signed certificate?
Select an answer first - 29
In a TLS cipher suite, which component is responsible for establishing a shared secret between the client and server without transmitting the secret itself?
Select an answer first - 30
A security engineer is configuring a TLS 1.2 server that must support clients using both RSA and ECDHE key exchange. The engineer wants to maximize security for clients that support ECDHE while maintaining compatibility for RSA-only clients. Which configuration should be used?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.