Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 4Objective 8

4.8 Interpret the Fields in Protocol Headers as Related to Intrusion Analysis 200-201 Practice Questions (Page 4)

Part of the 4.0 Network Intrusion Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)

32questions here
7free pages
10concepts
20%of the exam

Questions 16–20

  1. 16application · medium

    A security analyst is reviewing a DNS packet capture. The analyst sees a DNS query for 'example.com' with the QR flag set to 0, the RD flag set to 1, and the question section containing one entry. The source IP is 192.168.1.10 and the destination IP is 8.8.8.8. The source port is 54321 and the destination port is 53. Which field in the DNS header would the analyst examine to determine if this is a recursive query?

    Select an answer first
  2. 17application · medium

    An analyst is examining an Ethernet frame that contains an IPv4 packet. The EtherType field is 0x0800. The destination MAC address is 01:00:5e:00:00:01. What type of traffic is this?

    Select an answer first
  3. 18application · medium

    A network analyst is investigating a potential DNS amplification attack. The analyst sees a UDP packet with a source port of 53 and a destination port of 5353. The UDP length field is 512 bytes. The IP header shows a total length of 540 bytes and an IHL of 5. What is the size of the UDP payload?

    Select an answer first
  4. 19expert · hard

    A security analyst is reviewing a DNS capture from a compromised host. The DNS query is for 'malware.example.com' with QTYPE=A and RD=1. The response has QR=1, RCODE=0, and the Answer section contains an A record for 192.168.1.50. The analyst also sees a TCP connection from the host to 192.168.1.50 on port 4444. Which field in the DNS response is most useful for determining if this is a malicious response?

    Select an answer first
  5. 20application · medium

    An analyst is inspecting a TLS handshake in a packet capture. The analyst sees a ClientHello message that includes a list of cipher suites and a random value. The server responds with a ServerHello that selects one cipher suite and includes its own random value. Which field in the TLS handshake would the analyst examine to determine the version of TLS being used?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.