Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 3Objective 5

3.5 Interpret Operating System, SIEM, SOAR Platform, Application, or Command Line Logs to Identify an Event 200-201 Practice Questions (Page 2)

Part of the 3.0 Host-Based Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)

31questions here
7free pages
7concepts
20%of the exam

Questions 6–10

  1. 6application · medium

    A SIEM alert fires on a rule that detects 'multiple failed logins followed by a successful login'. The alert includes logs from a web application and the authentication server. Which SIEM feature would allow an analyst to see the full sequence of events across both sources in one view?

    Select an answer first
  2. 7application · medium

    A web server log shows the following entry: '192.168.1.50 - - [12/May/2024:10:15:23 +0000] "GET /admin/config.php HTTP/1.1" 200 5120 "http://192.168.1.50/admin/" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"'. The server is not indexed by search engines. Which part of the log entry is the strongest indicator that this request is suspicious?

    Select an answer first
  3. 8application · medium

    A SOC analyst is reviewing a SIEM alert that triggered on a single workstation. The alert is based on a correlation rule that counts failed logons (Event ID 4625) within a 10-minute window. The analyst sees 15 failed logons from the same source IP, followed by one successful logon (Event ID 4624) from the same IP. The user who owns the workstation is on vacation. Which conclusion is most supported by the log evidence?

    Select an answer first
  4. 9foundation · easy

    A log entry shows a user account successfully logging in at 3:00 AM from an IP address in a foreign country, while the user is known to be on vacation. Which type of event does this most likely indicate?

    Select an answer first
  5. 10application · medium

    A Windows administrator needs to find all PowerShell script executions in the last 24 hours from the security log. The administrator has PowerShell available. Which command will produce the most relevant results?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.