
CiscoCertified CyberOps Associate
Domain 3Objective 6
3.6 Interpret the Output Report of Malware Analysis Tools Such as a Detonation Chamber or Sandbox 200-201 Practice Questions (Page 5)
Part of the 3.0 Host-Based Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
7concepts
20%of the exam
Questions 21–25
- 21
An analyst reviews a sandbox report for a suspicious email attachment. The report shows the file created a copy of itself in %APPDATA%, added a Run registry key, and then spawned a process that made an HTTP POST to a remote IP. Which combination of report sections should the analyst prioritize to confirm the file is persistent and communicating externally?
Select an answer first - 22
A sandbox report shows a malware sample making DNS queries for a domain that resolves to an IP address in a cloud provider. The sample then connects to that IP on port 443 and sends encrypted data. The report also shows the sample creating a scheduled task that runs a script every 5 minutes. Which finding is the strongest indicator of a C2 channel?
Select an answer first - 23
An analyst is evaluating the reliability of a sandbox report that shows no malicious activity for a known malicious sample. Which report observations would explain the false negative? (Select all that apply.)
Select an answer first - 24
A sandbox report shows a binary that enumerates files with extensions .doc, .xls, .pdf, and .jpg, then attempts to connect to an external IP on port 21 (FTP). The binary also deletes the original files after the FTP transfer completes. Which malware category best matches this behavior?
Select an answer first - 25
A sandbox report for a suspicious document shows repeated DNS lookups for a domain that changes its IP address every few minutes, followed by HTTPS connections to those IPs on port 443. The document also created a scheduled task that runs a PowerShell script every hour. Which behavior is the strongest indicator of command-and-control communication?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.