
CiscoCertified CyberOps Associate
Domain 1Objective 8
1.8 Identify the Challenges of Data Visibility (network, Host, and Cloud) in Detection 200-201 Practice Questions (Page 1)
Part of the 1.0 Security Concepts domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
4concepts
20%of the exam
Questions 1–5
- 1
A security team deploys endpoint detection and response (EDR) agents on all company laptops and desktops. After a suspected breach, the team cannot find logs from a Linux server that was used as a jump host. The server is not running the EDR agent. What is the primary visibility gap in this scenario?
Select an answer first - 2
A security analyst is investigating a host that is suspected of being compromised. The host's EDR agent is reporting high CPU usage and is not responding to queries. The analyst suspects the attacker is using anti-forensics techniques. Which action would best help the analyst obtain visibility despite the unresponsive EDR agent?
Select an answer first - 3
A company has a hybrid environment with on-premises servers and cloud VMs. The security team uses a network IDS that only monitors the on-premises network. An attacker compromises a cloud VM and uses it to access on-premises resources through a VPN tunnel. Why might the IDS fail to detect the attacker's activities?
Select an answer first - 4
A security team is monitoring a cloud environment where developers frequently create and destroy virtual machines using infrastructure-as-code. The team notices that some VMs are only active for a few minutes and are not sending logs to the SIEM. What is the most effective way to improve visibility into these short-lived resources?
Select an answer first - 5
A security analyst is reviewing network traffic logs and notices that a workstation is communicating with a known command-and-control server using DNS. The analyst checks the host's EDR logs but finds no evidence of malware. What is the most likely reason for this discrepancy?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.