Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 4Objective 9

4.9 Interpret Common Artifact Elements from an Event to Identify an Alert 200-201 Practice Questions (Page 1)

Part of the 4.0 Network Intrusion Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
6concepts
20%of the exam

Questions 1–5

  1. 1application · medium

    An alert contains a file named invoice.exe with a SHA-256 hash that does not match any known malware. The analyst also sees a registry key created under HKCU\Software\Microsoft\Windows\CurrentVersion\Run. Which action is most appropriate?

    Select an answer first
  2. 2application · medium

    An analyst is reviewing an alert triggered by a workstation that contacted an external IP on TCP port 445. The alert shows the workstation's IP as the source and the external IP as the destination. The analyst also sees a URI in the event data: http://192.0.2.10/update. Which conclusion is best supported by these artifacts?

    Select an answer first
  3. 3foundation · easy

    An analyst has a file hash of a suspicious executable. Which action is most appropriate to determine if the file is known malware?

    Select an answer first
  4. 4expert · hard

    An analyst is reviewing a web proxy log entry: GET http://cdn.example-cdn.com/scripts/analytics.js HTTP/1.1 with a Referer header of http://www.example-bank.com/login. The analyst notices that the domain 'example-cdn.com' is a known content delivery network, but the IP address resolved for the domain is 203.0.113.45, which is flagged as malicious in threat intelligence. The bank's website is legitimate. Which interpretation is most accurate?

    Select an answer first
  5. 5application · medium

    An endpoint alert shows a process named wscript.exe making a call to ShellExecute with the parameter 'powershell -enc ...'. Which action is the process performing?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.