
CiscoCertified CyberOps Associate
Domain 4Objective 9
4.9 Interpret Common Artifact Elements from an Event to Identify an Alert 200-201 Practice Questions (Page 1)
Part of the 4.0 Network Intrusion Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
6concepts
20%of the exam
Questions 1–5
- 1
An alert contains a file named invoice.exe with a SHA-256 hash that does not match any known malware. The analyst also sees a registry key created under HKCU\Software\Microsoft\Windows\CurrentVersion\Run. Which action is most appropriate?
Select an answer first - 2
An analyst is reviewing an alert triggered by a workstation that contacted an external IP on TCP port 445. The alert shows the workstation's IP as the source and the external IP as the destination. The analyst also sees a URI in the event data: http://192.0.2.10/update. Which conclusion is best supported by these artifacts?
Select an answer first - 3
An analyst has a file hash of a suspicious executable. Which action is most appropriate to determine if the file is known malware?
Select an answer first - 4
An analyst is reviewing a web proxy log entry: GET http://cdn.example-cdn.com/scripts/analytics.js HTTP/1.1 with a Referer header of http://www.example-bank.com/login. The analyst notices that the domain 'example-cdn.com' is a known content delivery network, but the IP address resolved for the domain is 203.0.113.45, which is flagged as malicious in threat intelligence. The bank's website is legitimate. Which interpretation is most accurate?
Select an answer first - 5
An endpoint alert shows a process named wscript.exe making a call to ShellExecute with the parameter 'powershell -enc ...'. Which action is the process performing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.