
CiscoCertified CyberOps Associate
Domain 4Objective 9
4.9 Interpret Common Artifact Elements from an Event to Identify an Alert 200-201 Practice Questions (Page 7)
Part of the 4.0 Network Intrusion Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
6concepts
20%of the exam
Questions 31–35
- 31
An analyst is investigating an alert on a Linux server. The event log shows that a process named 'nginx' created a file in /tmp named 'x' and then made a call to execve with the argument '/bin/sh'. The file's SHA-256 hash is not in any threat feed. Which conclusion is best supported?
Select an answer first - 32
During an alert investigation, an analyst finds a file named 'svchost.exe' in the user's Startup folder. Why is this file considered suspicious?
Select an answer first - 33
An EDR alert shows a process 'rundll32.exe' calling the API 'WinExec' with the command 'cmd.exe /c net user hacker P@ssw0rd /add'. Which conclusion is best supported by this API call?
Select an answer first - 34
An analyst is investigating a beaconing alert. The flow shows a workstation sending periodic HTTPS requests to an external IP on port 443. The analyst also sees a file on the workstation with a SHA-256 hash that matches a known remote access trojan. Which conclusion is best supported?
Select an answer first - 35
An EDR alert shows a process 'winword.exe' making the following API calls: CreateFile on 'C:\Users\user\AppData\Local\Temp\macro.vbs', WriteFile, and then ShellExecute on 'macro.vbs'. The file hash of 'macro.vbs' is unknown. Which conclusion is best supported?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.