
CiscoCertified CyberOps Associate
Domain 4Objective 8
4.8 Interpret the Fields in Protocol Headers as Related to Intrusion Analysis 200-201 Practice Questions (Page 6)
Part of the 4.0 Network Intrusion Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
10concepts
20%of the exam
Questions 26–30
- 26
In an HTTP/1.1 request, which field is used to specify the domain name of the server being requested, allowing multiple websites to be hosted on the same IP address?
Select an answer first - 27
In an ARP packet, which field indicates whether the message is a request or a reply?
Select an answer first - 28
In the TLS handshake, which message is sent by the server to present its digital certificate to the client?
Select an answer first - 29
A security analyst is reviewing email traffic logs and sees a TCP session to port 25. The first command sent by the client is 'EHLO client.example.com'. The server responds with '250-AUTH LOGIN PLAIN'. Which protocol is being used and what does the server's response indicate?
Select an answer first - 30
A security analyst is investigating a potential port scan. The analyst sees a TCP packet with the SYN flag set and the destination port 22. The source port is 12345. The IP header shows a TTL of 64 and a total length of 40 bytes. The TCP header has a data offset of 5. What is the most likely purpose of this packet?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.