
CiscoCertified CyberOps Associate
Domain 4Objective 1
4.1 Map the Provided Events to Source Technologies 200-201 Practice Questions (Page 3)
Part of the 4.0 Network Intrusion Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 22 practice questions to prepare you well beyond it. (estimate)
22questions here
5free pages
6concepts
20%of the exam
Questions 11–15
- 11
A security analyst sees an event that says "Application 'BitTorrent' identified on session from 10.0.0.2 to 192.168.1.5, policy action: block". Which technology is the most likely source of this event?
Select an answer first - 12
Which event is most likely generated by an intrusion prevention system (IPS) rather than a firewall or proxy?
Select an answer first - 13
An analyst is triaging an alert that shows a signature match for a known exploit against a web server. The alert includes the raw packet payload. Which source technology is the most likely origin of this alert?
Select an answer first - 14
A security analyst is reviewing logs from a single network appliance. The logs show entries like 'alert tcp $EXTERNAL_NET any -> $HOME_NET 445 (msg:"ET TROJAN Possible Metasploit payload download"; flow:established,to_client; content:"|ff d8 ff e0|";)' and also entries that show 'allow' or 'deny' actions tied to specific rule IDs. The analyst needs to determine which two technologies generated these logs. Which pair of source technologies is most likely represented?
Select an answer first - 15
Which event is most likely generated by a proxy server?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.