Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 3Objective 6

3.6 Interpret the Output Report of Malware Analysis Tools Such as a Detonation Chamber or Sandbox 200-201 Practice Questions (Page 4)

Part of the 3.0 Host-Based Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
7concepts
20%of the exam

Questions 16–20

  1. 16application · medium

    A sandbox report shows a malware sample making DNS queries for 'update.legit-service.com' and then connecting to an IP address in a different country on port 8443. The report also shows the malware uploading a file named 'credentials.txt' to that IP. Which finding is the strongest indicator of data exfiltration?

    Select an answer first
  2. 17application · medium · select all that apply

    A sandbox report for a malicious document contains the following items. Which items should be extracted as IOCs for detection? (Select all that apply.)

    Select an answer first
  3. 18application · medium

    An analyst reviews a sandbox report for a malicious binary. The report lists the file's SHA-256 hash, several IP addresses contacted, a domain name, and a file path where the binary dropped a DLL. Which item from the report is most useful as a host-based IOC for detecting the malware on other endpoints?

    Select an answer first
  4. 19expert · hard

    An analyst is reviewing a sandbox report that shows no malicious behavior, but the sample is known to be malicious from prior intelligence. The report indicates the sample checked for the presence of a specific USB drive and then terminated. Which conclusion is most accurate?

    Select an answer first
  5. 20application · medium · select all that apply

    A sandbox report shows network activity from a suspicious process. Which findings are strong indicators of data exfiltration? (Select all that apply.)

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.