
CiscoCertified CyberOps Associate
Domain 4Objective 8
4.8 Interpret the Fields in Protocol Headers as Related to Intrusion Analysis 200-201 Practice Questions (Page 7)
Part of the 4.0 Network Intrusion Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
10concepts
20%of the exam
Questions 31–32
- 31
An analyst is reviewing a DNS response packet. The source port is 53 and the destination port is 5353. The UDP length field is 512 bytes. The DNS header shows the QR flag set to 1 and the TC flag set to 1. What does the TC flag indicate?
Select an answer first - 32
A security analyst is reviewing a packet capture and sees an IPv4 packet with the header fields: IHL=5, total length=1500, identification=0x1A2B, flags=0x2 (Don't Fragment set), fragment offset=0, TTL=64, protocol=6, and a TCP segment inside. The analyst notes the TCP header has a data offset of 5 and the flags field shows SYN and ACK set. The destination IP is a public web server. Which conclusion is most defensible from these fields alone?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to 200-201
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.