Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 3Objective 5

3.5 Interpret Operating System, SIEM, SOAR Platform, Application, or Command Line Logs to Identify an Event 200-201 Practice Questions (Page 3)

Part of the 3.0 Host-Based Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)

31questions here
7free pages
7concepts
20%of the exam

Questions 11–15

  1. 11expert · hard

    A SOC team is investigating a series of alerts. The SIEM shows the following events for a single workstation: 10:00:00 - Failed logon for user 'admin' from IP 203.0.113.5; 10:00:05 - Failed logon for user 'admin' from IP 203.0.113.5; 10:00:10 - Successful logon for user 'admin' from IP 203.0.113.5; 10:00:15 - Process creation: 'cmd.exe' with parent 'winlogon.exe'; 10:00:20 - Process creation: 'powershell.exe' with parent 'cmd.exe'. The organization has a policy that administrative accounts must not be used for interactive logons. The analyst needs to determine if this is a true positive and what the next step should be. Which conclusion is most accurate?

    Select an answer first
  2. 12foundation · easy

    A security analyst uses a SIEM platform to detect a brute-force attack. Which SIEM capability is most directly used to identify the attack?

    Select an answer first
  3. 13foundation · easy

    A Windows administrator wants to review security-related events such as successful and failed logon attempts. Which Windows tool should they use?

    Select an answer first
  4. 14foundation · easy

    Which log component is most important for correlating events across multiple systems in a security investigation?

    Select an answer first
  5. 15application · medium

    A SOC analyst is investigating an alert in the SIEM that shows a single workstation making outbound connections to a known malicious IP address. The SIEM also shows that a SOAR playbook automatically blocked the IP on the firewall. The analyst wants to confirm that the block was effective. Which SIEM data should the analyst review?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.