Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 1Objective 8

1.8 Identify the Challenges of Data Visibility (network, Host, and Cloud) in Detection 200-201 Practice Questions (Page 3)

Part of the 1.0 Security Concepts domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)

33questions here
7free pages
4concepts
20%of the exam

Questions 11–15

  1. 11application · medium

    A security analyst notices that the IDS is not generating alerts for a known malware family that communicates over HTTPS. The network team confirms that the firewall is logging connections, but the IDS sees only the TLS handshake. Which action would most directly improve visibility into this traffic?

    Select an answer first
  2. 12expert · hard · select all that apply

    A security team is investigating a potential malware outbreak. The team has EDR agents on most endpoints, but some endpoints are not covered. The team also has network flow logs and cloud API logs. Which of the following are likely consequences of the incomplete host visibility? (Select all that apply.)

    Select an answer first
  3. 13expert · hard · select all that apply

    A security team is trying to improve detection capabilities across network, host, and cloud. The team has limited budget and must prioritize. Which of the following are effective ways to address visibility gaps? (Select all that apply.)

    Select an answer first
  4. 14application · medium

    A security analyst is investigating a potential compromise in a cloud environment. The attacker created a VM, used it for a few minutes, and then deleted it. The analyst checks the cloud provider's activity logs and finds API calls that created and deleted the VM, but no OS-level logs from the VM itself. What is the primary reason for this visibility gap?

    Select an answer first
  5. 15application · medium

    A security team discovers that an attacker has been exfiltrating data from a server for three weeks. The team has network flow logs and host authentication logs, but no packet captures or process-level logs. What is the most likely impact of these visibility gaps on the investigation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.