
CiscoCertified CyberOps Associate
Domain 4Objective 9
4.9 Interpret Common Artifact Elements from an Event to Identify an Alert 200-201 Practice Questions (Page 3)
Part of the 4.0 Network Intrusion Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
6concepts
20%of the exam
Questions 11–15
- 11
An analyst is investigating an alert that shows a file downloaded from a URL. The file's MD5 hash matches a known malware signature, but the SHA-256 hash does not match any known threat. The analyst also sees that the URL is a legitimate software vendor's site. Which conclusion is most appropriate?
Select an answer first - 12
A SOC analyst is reviewing an alert that shows a workstation at 10.0.0.50 communicating with a server at 203.0.113.20. The flow shows source port 12345 and destination port 443. The analyst also sees a DNS query for 'update.example.com' resolving to 203.0.113.20. The domain is not on any threat list, but the IP is in a known malicious range. Which interpretation is most accurate?
Select an answer first - 13
A network analyst is reviewing an alert that shows a server at 192.168.1.10 sending a large amount of data to 203.0.113.77 on TCP port 22. The analyst also sees a DNS query for 'backup.example.com' resolving to 203.0.113.77. The domain is not on any threat list, but the volume of data is unusual for the server. Which interpretation is most accurate?
Select an answer first - 14
During an incident, an analyst examines a Windows event log entry for a process named svchost.exe. The event shows the process created a file named C:\Users\Public\update.exe and then made a call to WinExec. The file's SHA-256 hash matches a known malware signature. Which set of artifacts most strongly indicates malicious activity?
Select an answer first - 15
A security analyst is investigating a suspicious file downloaded from an email attachment. The analyst computes the MD5, SHA-1, and SHA-256 hashes of the file. Which statement about using these hashes for threat identification is correct?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.