Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 3Objective 5

3.5 Interpret Operating System, SIEM, SOAR Platform, Application, or Command Line Logs to Identify an Event 200-201 Practice Questions (Page 6)

Part of the 3.0 Host-Based Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)

31questions here
7free pages
7concepts
20%of the exam

Questions 26–30

  1. 26foundation · easy

    A Linux analyst wants to extract only the lines from a log file that contain the word "ERROR". Which command-line tool is most appropriate?

    Select an answer first
  2. 27application · medium

    An application log shows repeated entries: 'ERROR: Connection timeout to database' every 5 seconds for 10 minutes, followed by 'INFO: Connection restored'. Which event does this log pattern most likely indicate?

    Select an answer first
  3. 28application · medium

    A SOAR platform log shows that a playbook ran and executed the action 'Block IP' on a firewall. The log entry includes the trigger: 'SIEM alert: Malware C2 beacon detected'. Which SOAR log field would be most important to verify that the correct IP was blocked?

    Select an answer first
  4. 29expert · hard

    A SOC analyst is reviewing SOAR logs after a playbook ran automatically. The playbook was triggered by a SIEM alert for 'possible malware beaconing'. The playbook actions were: 1) Query the endpoint for running processes, 2) Check the process hash against a threat intelligence feed, 3) If malicious, quarantine the endpoint. The SOAR log shows that the process hash was not found in the threat intelligence feed, so the playbook did not quarantine the endpoint. However, the analyst later determines that the process is indeed malicious based on other indicators. What is the most significant limitation of the playbook?

    Select an answer first
  5. 30application · medium

    A SOAR platform log shows that a playbook automatically quarantined a workstation after a SIEM alert. The playbook log entry includes: 'Trigger: SIEM alert ID 12345', 'Action: Isolate host', 'Status: Success'. Which additional piece of information in the SOAR log would be most useful for a SOC analyst to determine if the action was appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.