
CiscoCertified CyberOps Associate
Domain 3Objective 6
3.6 Interpret the Output Report of Malware Analysis Tools Such as a Detonation Chamber or Sandbox 200-201 Practice Questions (Page 1)
Part of the 3.0 Host-Based Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
7concepts
20%of the exam
Questions 1–5
- 1
A sandbox report shows the malware encrypting files and displaying a ransom note. Which malware category does this behavior most strongly indicate?
Select an answer first - 2
A sandbox report for a Windows executable shows that it created a service named 'WindowsUpdateSvc', modified the security policy to disable Windows Defender, and then deleted the original executable. Which malware category does this behavior most strongly indicate?
Select an answer first - 3
A sandbox report shows no malicious activity for a file, but the analyst suspects the malware is evasive. Which report observation would most strongly support that suspicion?
Select an answer first - 4
Why might a sandbox report fail to show malicious behavior even though the sample is known malware?
Select an answer first - 5
A sandbox report shows no network activity for a malware sample, but the analyst knows the malware is designed to exfiltrate data. Which limitation of sandbox analysis is most likely responsible for the lack of network activity?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.