
CiscoCertified CyberOps Associate
Domain 1Objective 10
1.10 Interpret the 5-Tuple Approach to Isolate a Compromised Host in a Grouped Set of Logs 200-201 Practice Questions (Page 3)
Part of the 1.0 Security Concepts domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)
20questions here
4free pages
4concepts
20%of the exam
Questions 11–15
- 11
An analyst is examining logs grouped by 5-tuple and notices a single host communicating with an external IP on port 4444 using TCP. The traffic is periodic and low-volume. What should the analyst suspect?
Select an answer first - 12
A SOC analyst is investigating a host that is suspected of data exfiltration. The logs show the host communicating with an external IP on port 443 using TCP, but the traffic volume is very high and occurs at odd hours. The analyst also notices that the host is making DNS queries to a domain that is not in the corporate allowlist. Which 5-tuple pattern is most indicative of data exfiltration?
Select an answer first - 13
A network administrator is analyzing proxy logs to identify all web traffic from a specific user's workstation. The workstation has a dynamic IP address assigned via DHCP. Which additional information is needed to accurately group the logs by the workstation's 5-tuple?
Select an answer first - 14
A SOC is investigating a host that is suspected of being compromised. The logs show the following 5-tuples for the host: (10.0.0.5, 8.8.8.8, 12345, 53, UDP), (10.0.0.5, 8.8.8.8, 12346, 53, UDP), (10.0.0.5, 8.8.8.8, 12347, 53, UDP), and (10.0.0.5, 8.8.8.8, 12348, 53, UDP). The analyst also sees a single TCP connection to 203.0.113.5 on port 4444. Which conclusion is most supported by the 5-tuple analysis?
Select an answer first - 15
A security analyst is reviewing firewall logs and sees a large number of entries with the same source IP and destination IP but different destination ports. The analyst suspects a port scan. Which 5-tuple field is most useful to confirm this pattern?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.