
CiscoCertified CyberOps Associate
Domain 4Objective 9
4.9 Interpret Common Artifact Elements from an Event to Identify an Alert 200-201 Practice Questions (Page 4)
Part of the 4.0 Network Intrusion Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
6concepts
20%of the exam
Questions 16–20
- 16
A security analyst is reviewing a proxy log entry: 2024-05-01 10:00:00, source IP 10.1.1.50, destination IP 203.0.113.5, URL http://203.0.113.5/payload.bin. The analyst notices the URL uses the IP address instead of a domain name. Which interpretation is most accurate?
Select an answer first - 17
An alert shows that a process named 'svchost.exe' in a user's AppData\Roaming folder created a file called 'update.exe' and then modified the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run. The file hash of 'update.exe' matches a known malware signature. Which artifact element is the strongest indicator that this is malicious persistence?
Select an answer first - 18
A security analyst is reviewing an endpoint detection and response (EDR) alert for a process that made the following system API calls: CreateFile on C:\Users\Public\payload.exe, WriteFile, and then CreateProcess on the same file. Which conclusion is best supported by these API calls?
Select an answer first - 19
An analyst is examining a proxy log entry: GET http://www.example.com/update.php?id=123 HTTP/1.1 with a Host header of www.example.com. The analyst notices that the domain 'example.com' is a known malicious domain. Which part of the URL is the most direct indicator of compromise?
Select an answer first - 20
An analyst is reviewing an alert where the source IP is a public address and the destination IP is a private address. What does this pairing typically indicate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.