
CiscoCertified CyberOps Associate
Domain 2Objective 2
2.2 Identify the Types of Data Provided by These Technologies 200-201 Practice Questions (Page 1)
Part of the 2.0 Security Monitoring domain, which accounts for 25% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
7concepts
25%of the exam
Questions 1–5
- 1
A stateful firewall logs an entry showing that a TCP connection was established and then terminated normally. What type of data does this log represent?
Select an answer first - 2
A network analyst is troubleshooting a slow application and needs to see the exact TCP handshake and the first 100 bytes of each packet exchanged with the server. The analyst also wants a summary of all connections by source/destination IP and port to identify which hosts are generating the most traffic. Which two data sources should the analyst use?
Select an answer first - 3
A web content filter logs that a user attempted to access a URL categorized as 'Phishing' and the request was blocked. Which data types are present in this log?
Select an answer first - 4
An NGFW logs an event that includes the username of the employee who initiated a web request. Which type of data is this?
Select an answer first - 5
A security team needs to identify which users are using a specific cloud storage application and whether any of that usage triggered an intrusion prevention alert. Which technology provides the most direct data for this analysis?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.