
CiscoCertified CyberOps Associate
Domain 3Objective 6
3.6 Interpret the Output Report of Malware Analysis Tools Such as a Detonation Chamber or Sandbox 200-201 Practice Questions (Page 7)
Part of the 3.0 Host-Based Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
7concepts
20%of the exam
Questions 31–35
- 31
Which section of a sandbox report would show the domains and IP addresses contacted by the malware during execution?
Select an answer first - 32
A sandbox report shows the malware creating multiple copies of itself on the local network and attempting to spread to other hosts. Which malware category does this behavior indicate?
Select an answer first - 33
A sandbox report for a PDF file shows that it spawned a child process (cmd.exe) that executed a script to download a file from a remote server and save it as 'invoice.exe' in the Temp folder. The PDF itself did not perform any file writes. Which statement best describes the malicious behavior?
Select an answer first - 34
In a typical sandbox report, which section would provide details about the file's hash, size, and file type?
Select an answer first - 35
Which limitation of sandbox analysis is most likely to cause a false negative when analyzing a malware sample that only activates after a specific date?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.