
CiscoCertified CyberOps Associate
Domain 4Objective 8
4.8 Interpret the Fields in Protocol Headers as Related to Intrusion Analysis 200-201 Practice Questions (Page 5)
Part of the 4.0 Network Intrusion Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
10concepts
20%of the exam
Questions 21–25
- 21
While analyzing a captured IPv6 packet, a security analyst observes the following header fields: Version = 6, Traffic Class = 0x00, Flow Label = 0x00000, Payload Length = 40, Next Header = 6, Hop Limit = 64, Source Address = 2001:db8::1, Destination Address = 2001:db8::2. Which statement correctly interprets these fields?
Select an answer first - 22
An analyst notices an ARP reply that claims the sender's IP address is 192.168.1.1, but the sender's MAC address is different from the legitimate gateway's MAC. What type of attack is likely occurring?
Select an answer first - 23
Which protocol is used by an email client to retrieve messages from a server while typically leaving a copy of the messages on the server?
Select an answer first - 24
A SOC analyst is examining a DNS capture from an internal client. The DNS header shows: QR=0, Opcode=0, RD=1, and the Question section contains a single query for 'update.example.com' with QTYPE=A. The response (QR=1) has RCODE=0 and the Answer section contains an A record pointing to 10.10.10.5. The analyst also sees a TCP SYN from the client to 10.10.10.5 on port 53 immediately after. What does this sequence indicate?
Select an answer first - 25
A SOC analyst is investigating a possible denial-of-service attack. The capture shows a flood of IPv4 packets with the following characteristics: TTL=64, protocol=6 (TCP), source IP=203.0.113.5, destination IP=198.51.100.10, TCP flags=SYN, and the IP identification field increments by 1 for each packet. The analyst also notices that the TCP window size is consistently 1024. Which observation is most indicative of a crafted attack rather than a legitimate connection attempt?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.