
CiscoCertified CyberOps Associate
Domain 4Objective 8
4.8 Interpret the Fields in Protocol Headers as Related to Intrusion Analysis 200-201 Practice Questions (Page 2)
Part of the 4.0 Network Intrusion Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
10concepts
20%of the exam
Questions 6–10
- 6
An analyst is investigating a potential DNS tunneling attack. The analyst sees a DNS query for 'abcdefghijklmnopqrstuvwxyz.example.com' with a query type of TXT. The response contains a TXT record with a long string of base64-encoded data. The source IP is 192.168.1.10 and the destination IP is 8.8.8.8. Which field in the DNS message would the analyst examine to determine if the response is from a legitimate DNS server?
Select an answer first - 7
An analyst is investigating a suspected ARP spoofing attack. The analyst sees an ARP reply packet with the sender hardware address 00:11:22:33:44:55 and the sender protocol address 192.168.1.1. The target hardware address is 00:aa:bb:cc:dd:ee and the target protocol address is 192.168.1.10. The Ethernet frame has a source MAC of 00:11:22:33:44:55 and a destination MAC of 00:aa:bb:cc:dd:ee. Which observation would most strongly indicate that this is an unsolicited ARP reply?
Select an answer first - 8
A security analyst is examining a packet capture that shows a TCP connection to a web server. The client sends a SYN packet with a TTL of 64 and an IP identification of 0x1234. The server responds with a SYN-ACK. The client then sends an ACK, followed by an HTTP GET request. The analyst notices that the IP identification field in the client's subsequent packets is incrementing by 1. What is the most likely explanation for this pattern?
Select an answer first - 9
Which flag in the DNS header indicates that the message is a response to a query?
Select an answer first - 10
An analyst is examining an ICMP packet that has a type field of 8 and a code field of 0. The IP header shows a TTL of 64 and a protocol field of 1. The ICMP payload contains a timestamp. What is the most likely purpose of this packet?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.