Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 1Objective 10

1.10 Interpret the 5-Tuple Approach to Isolate a Compromised Host in a Grouped Set of Logs 200-201 Practice Questions (Page 1)

Part of the 1.0 Security Concepts domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)

20questions here
4free pages
4concepts
20%of the exam

Questions 1–5

  1. 1expert · hard

    An analyst is reviewing logs from a network that uses a load balancer. The analyst is trying to isolate traffic from a specific internal host. Which challenge does the analyst face when using the 5-tuple?

    Select an answer first
  2. 2expert · hard

    An incident responder needs to isolate all traffic from a compromised host that is behind a NAT gateway. The host's private IP is known, but the firewall logs show only the public IP of the NAT gateway. Which additional information is needed to accurately isolate the host's traffic?

    Select an answer first
  3. 3foundation · medium

    A network analyst is reviewing a packet capture to document the communication session between a workstation and a web server. The analyst records the workstation's IP address (192.168.10.25), the web server's IP address (203.0.113.10), the workstation's ephemeral port (49152), the web server's port (443), and the transport protocol (TCP). Which of the following best describes what the analyst has documented?

    Select an answer first
  4. 4expert · hard

    An analyst is reviewing logs from a network that uses NAT. The analyst is trying to isolate traffic from a specific internal host behind the NAT. Which challenge does the analyst face when using the 5-tuple?

    Select an answer first
  5. 5application · medium

    A SOC analyst is examining a grouped set of firewall logs for a single host. The logs show the host connecting to many different destination IP addresses on port 445 over a short period. Which conclusion is most consistent with this pattern?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.