Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 4Objective 8

4.8 Interpret the Fields in Protocol Headers as Related to Intrusion Analysis 200-201 Practice Questions (Page 1)

Part of the 4.0 Network Intrusion Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)

32questions here
7free pages
10concepts
20%of the exam

Questions 1–5

  1. 1application · medium

    An analyst is examining a packet capture and sees an ICMPv4 packet with type=8, code=0, checksum=0x4d5a, and a payload that contains the ASCII string 'ping'. The IP header shows TTL=128, protocol=1, source=10.0.0.1, destination=10.0.0.2. What does this packet represent?

    Select an answer first
  2. 2expert · hard

    An analyst is investigating a network anomaly. The capture shows a series of ARP requests from a single host (MAC 00:11:22:33:44:55) asking 'Who has 192.168.1.1?' and 'Who has 192.168.1.2?' and so on, for every IP in the subnet, all within a few seconds. The analyst also sees an ARP reply from the same host claiming to be 192.168.1.1. What is the most likely explanation for this behavior?

    Select an answer first
  3. 3application · medium

    An analyst is investigating a suspected ARP spoofing attack on a local subnet. The capture shows an ARP packet with: hardware type=1, protocol type=0x0800, hardware size=6, protocol size=4, opcode=2 (reply), sender MAC=00:11:22:33:44:55, sender IP=192.168.1.1, target MAC=ff:ff:ff:ff:ff:ff, target IP=192.168.1.100. The analyst knows the legitimate gateway is at 192.168.1.1 with MAC 00:aa:bb:cc:dd:ee. What is the most significant anomaly in this ARP packet?

    Select an answer first
  4. 4application · medium

    An email security analyst is examining a capture of SMTP traffic. The analyst sees the following commands: EHLO mail.example.com, MAIL FROM:<attacker@example.com>, RCPT TO:<victim@company.com>, DATA, and then the message body. The analyst notices that the 'Received:' header in the message body shows a different source IP than the SMTP connection's source IP. What does this discrepancy indicate?

    Select an answer first
  5. 5application · medium

    A security analyst is reviewing a TCP capture and sees a segment with the following header fields: source port=12345, destination port=80, sequence number=1000, acknowledgment number=0, data offset=5, flags=SYN, window size=65535, checksum=0xabcd, urgent pointer=0. The IP header shows protocol=6, source=192.168.1.10, destination=93.184.216.34. What is the most accurate interpretation of this segment?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.