
CiscoCertified CyberOps Associate
Domain 1Objective 8
1.8 Identify the Challenges of Data Visibility (network, Host, and Cloud) in Detection 200-201 Practice Questions (Page 2)
Part of the 1.0 Security Concepts domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
4concepts
20%of the exam
Questions 6–10
- 6
A SOC lacks visibility into a cloud environment because the cloud provider does not expose certain logs to the customer. An attacker exploits this gap to perform unauthorized actions. What is the most likely consequence for the SOC's detection capability?
Select an answer first - 7
A security team relies on a network-based IDS placed at the internet edge. An attacker moves laterally between internal servers using SMB, and the IDS does not alert. The team later discovers the breach through a host-based alert. What is the most likely reason the IDS missed the lateral movement?
Select an answer first - 8
A security team is designing monitoring for a network that carries sensitive customer data. The team wants to inspect all traffic for threats, but the legal department requires that employee web traffic remain private and not be decrypted. The team also needs to detect malware that uses HTTPS for command-and-control. Which approach best balances these requirements?
Select an answer first - 9
A security analyst is reviewing network telemetry and notices that a large portion of internal web traffic is not being inspected by the intrusion detection system. The traffic is between internal clients and a public SaaS application. The analyst confirms the firewall is logging connections and the IDS is receiving a copy of the traffic via a SPAN port. What is the most likely reason the IDS is missing this traffic?
Select an answer first - 10
A company uses a multi-cloud environment with workloads in AWS and Azure. The security team is trying to centralize visibility by sending logs from both clouds to a SIEM. The team notices that some AWS CloudTrail events are missing, while Azure activity logs are complete. What is the most likely cause of this discrepancy?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.