
CiscoCertified CyberOps Associate
Domain 4Objective 8
4.8 Interpret the Fields in Protocol Headers as Related to Intrusion Analysis 200-201 Practice Questions (Page 1)
Part of the 4.0 Network Intrusion Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
10concepts
20%of the exam
Questions 1–5
- 1
An analyst is examining a packet capture and sees an ICMPv4 packet with type=8, code=0, checksum=0x4d5a, and a payload that contains the ASCII string 'ping'. The IP header shows TTL=128, protocol=1, source=10.0.0.1, destination=10.0.0.2. What does this packet represent?
Select an answer first - 2
An analyst is investigating a network anomaly. The capture shows a series of ARP requests from a single host (MAC 00:11:22:33:44:55) asking 'Who has 192.168.1.1?' and 'Who has 192.168.1.2?' and so on, for every IP in the subnet, all within a few seconds. The analyst also sees an ARP reply from the same host claiming to be 192.168.1.1. What is the most likely explanation for this behavior?
Select an answer first - 3
An analyst is investigating a suspected ARP spoofing attack on a local subnet. The capture shows an ARP packet with: hardware type=1, protocol type=0x0800, hardware size=6, protocol size=4, opcode=2 (reply), sender MAC=00:11:22:33:44:55, sender IP=192.168.1.1, target MAC=ff:ff:ff:ff:ff:ff, target IP=192.168.1.100. The analyst knows the legitimate gateway is at 192.168.1.1 with MAC 00:aa:bb:cc:dd:ee. What is the most significant anomaly in this ARP packet?
Select an answer first - 4
An email security analyst is examining a capture of SMTP traffic. The analyst sees the following commands: EHLO mail.example.com, MAIL FROM:<attacker@example.com>, RCPT TO:<victim@company.com>, DATA, and then the message body. The analyst notices that the 'Received:' header in the message body shows a different source IP than the SMTP connection's source IP. What does this discrepancy indicate?
Select an answer first - 5
A security analyst is reviewing a TCP capture and sees a segment with the following header fields: source port=12345, destination port=80, sequence number=1000, acknowledgment number=0, data offset=5, flags=SYN, window size=65535, checksum=0xabcd, urgent pointer=0. The IP header shows protocol=6, source=192.168.1.10, destination=93.184.216.34. What is the most accurate interpretation of this segment?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.