What are two categories of DDoS attacks? (Choose two.)
Reveal answer details Close answer details
Correct answersA, B
Cisco ยท 200-201
Review the question wording, option layout, and available explanations before choosing a study plan.
|
Multiple choice
What are two categories of DDoS attacks? (Choose two.) Reveal answer details Close answer detailsCorrect answersA, B
Single choice
Syslog collecting software is installed on the server For the log containment, a disk with FAT type partition is used An engineer determined that log files are being corrupted when the 4 GB tile size is exceeded. Which action resolves the issue? Reveal answer details Close answer detailsCorrect answerD
Single choice
Which SOC metric represents the time to stop the incident from causing further damage to systems or data? Reveal answer details Close answer detailsCorrect answerC
Single choice
Refer to the exhibit. ![]() An attacker scanned the server using Nmap. What did the attacker obtain from this scan? Reveal answer details Close answer detailsCorrect answerA
Single choice
Which security monitoring data type requires the largest storage space? Reveal answer details Close answer detailsCorrect answerD
Single choice
Which type of evidence supports a theory or an assumption that results from initial evidence? Reveal answer details Close answer detailsCorrect answerD Explanation Corroborating evidence (or corroboration) is evidence that tends to support a theory or an assumption deduced by some initial evidence. This corroborating evidence confirms the proposition. Cisco CyberOps Associate CBROPS 200-201 Official Cert Guide
Single choice
What is the difference between deep packet inspection and stateful inspection? Reveal answer details Close answer detailsCorrect answerD
Single choice
Which HTTP header field is used in forensics to identify the type of browser used? Reveal answer details Close answer detailsCorrect answerC Explanation User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:12.0) Gecko/20100101 Firefox/12.0 In computing, a user agent is any software, acting on behalf of a user, which "retrieves, renders and facilitates end-user interaction with Web content".[1] A user agent is therefore a special kind of software agent.
Single choice
Which evasion method involves performing actions slower than normal to prevent detection? Reveal answer details Close answer detailsCorrect answerA Explanation A timing attack involves performing actions slower than normal to avoid detection by security systems. By slowing down the process, attackers may try to avoid triggering thresholds or detection mechanisms that rely on normal or faster behaviors.
Single choice
What is the difference between statistical detection and rule-based detection models? Reveal answer details Close answer detailsCorrect answerB
Single choice
Which security principle requires more than one person is required to perform a critical task? Reveal answer details Close answer detailsCorrect answerC
Single choice
What does the Zero Trust security model signify? Reveal answer details Close answer detailsCorrect answerA
Single choice
Refer to the exhibit. ![]() Which event is occurring? Reveal answer details Close answer detailsCorrect answerB Explanation https://cuckoo.readthedocs.io/en/latest/usage/submit/
Single choice
Which technology prevents end-device to end-device IP traceability? Reveal answer details Close answer detailsCorrect answerC
Single choice
An analyst is investigating an incident in a SOC environment. Which method is used to identify a session from a group of logs? Reveal answer details Close answer detailsCorrect answerC
Single choice
An engineer must create a SIEM rule to test events and traffic for spikes and changes that occur in regular patterns to detect irregularities. Which rules achieve the desired results? Reveal answer details Close answer detailsCorrect answerB
Single choice
How does the approach of a behavioral detection system to identifying security threats compare to that of a rule-based detection system? Reveal answer details Close answer detailsCorrect answerC
Single choice
An offline audit log contains the source IP address of a session suspected to have exploited a vulnerability resulting in system compromise. Which kind of evidence is this IP address? Reveal answer details Close answer detailsCorrect answerB
Multiple choice
Which two elements are used for profiling a network? (Choose two.) Reveal answer details Close answer detailsCorrect answersA, B Explanation A network profile should include some important elements, such as the following: Total throughput the amount of data passing from a given source to a given destination in a given period of time Session duration the time between the establishment of a data flow and its termination Ports used a list of TCP or UDP processes that are available to accept data Critical asset address space the IP addresses or the logical location of essential systems or data Profiling data are data that system has gathered, these data helps for incident response and to detect
Single choice
Refer to the exhibit ![]() A SOC analyst is examining the Auth.log file logs of one the breached systems What is the possible reason for this event log? Reveal answer details Close answer detailsCorrect answerB
Single choice
What is a description of a man-in-the-middle network attack? Reveal answer details Close answer detailsCorrect answerC
Single choice
Which type of evidence directly proves a fact without inference? Reveal answer details Close answer detailsCorrect answerC Explanation Direct evidence is evidence that directly proves a fact without requiring any inference or interpretation. For example, a log entry showing a specific user executing a malicious command would be considered direct evidence. Circumstantial evidence (A) requires inference to connect it to a conclusion, such as logs indicating unusual activity that suggests an attack. Indirect evidence (B) is similar to circumstantial evidence. Corroborative evidence (D) supports other evidence but does not independently prove a fact. In cybersecurity investigations, direct evidence is highly valuable because it provides clear and definitive proof of an event or action. However, many investigations rely on a combination of evidence types to build a comprehensive understanding of an incident. Proper evidence classification is important for legal and forensic processes.
Single choice
What is the difference between a vulnerability and an attack surface? Reveal answer details Close answer detailsCorrect answerA
Single choice
What is the communication channel established from a compromised machine back to the attacker? Reveal answer details Close answer detailsCorrect answerB
Single choice
An analyst performs traffic analysis to detect suspicious activity and identifies the multiple UDP connections through the same port. Which technology makes this behavior feasible? Reveal answer details Close answer detailsCorrect answerC
Single choice
An engineer must investigate suspicious connections. Data has been gathered using a tcpdump command on a Linux device and saved as sandboxmalware2022-12-22.pcaps file. The engineer is trying to open the tcpdump in the Wireshark tool. What is the expected result? Reveal answer details Close answer detailsCorrect answerA
Single choice
Which element is included in an incident response plan as stated in NIST.SP800-617 Reveal answer details Close answer detailsCorrect answerD
Multiple choice
A software development company develops high-end technology for the customer that will go through the HIPAA audit program. The technology will be hosted in the cloud, and the healthcare, employee names, and contact information will be stored on two separate logically isolated private cloud services. The patents and inventions will be hosted on a separate encrypted database. A compliance team is asked to analyze the cloud infrastructure and architecture to identify the protected data. Which two types of protected data should be identified? (Choose two.) Reveal answer details Close answer detailsCorrect answersB, C
Single choice
What describes the usage of a rootkit in endpoint-based attacks? Reveal answer details Close answer detailsCorrect answerD
Single choice
What is a description of "phishing" as a social engineering attack? Reveal answer details Close answer detailsCorrect answerB
Single choice
A user reports difficulties accessing certain external web pages. When an engineer examines traffic to and from the external domain in full packet captures, they notice that many SYNs have the same sequence number, source, and destination IP address, but they have different payloads. What is causing this situation? Reveal answer details Close answer detailsCorrect answerD
Single choice
A security specialist is investigating an incident regarding a recent major breach in the organization. The accounting data from a 24-month period is affected due to a trojan detected in a department's critical server. A security analyst investigates the incident and discovers that an incident response team member who detected a trojan during regular AV scans had made an image of the server for evidence purposes. Which type of evidence is the security analyst dealing with? Reveal answer details Close answer detailsCorrect answerD
Single choice
Which information must an organization use to understand the threats currently targeting the organization? Reveal answer details Close answer detailsCorrect answerA
Single choice
What is the difference between an attack vector and attack surface? Reveal answer details Close answer detailsCorrect answerC
Single choice
What is the difference between vulnerability and risk? Reveal answer details Close answer detailsCorrect answerD
Single choice
A company receptionist received a threatening call referencing stealing assets and did not take any action assuming it was a social engineering attempt. Within 48 hours, multiple assets were breached, affecting the confidentiality of sensitive information. What is the threat actor in this incident? Reveal answer details Close answer detailsCorrect answerC
Single choice
According to NIST, at which step of the incident response process should an organization apply lessons learned from practice? Reveal answer details Close answer detailsCorrect answerD
Single choice
A user received a malicious email attachment named "DS045-report1122345.exe" and executed it. Reveal answer details Close answer detailsCorrect answerD Explanation The attachment is already executed. It should be Exploitation, but once it is not an option so it is installation.
Single choice
What is a difference between SIEM and SOAR? Reveal answer details Close answer detailsCorrect answerB Explanation References:
Single choice
Where is a host-based intrusion detection system located? Reveal answer details Close answer detailsCorrect answerD
Single choice
Refer to the exhibit. ![]() An engineer needs to identify certificate information on server1234567890. What does the exhibit indicate? Reveal answer details Close answer detailsCorrect answerA
Multiple choice
What are two types of cross site scripting attacks? (Choose two.) Reveal answer details Close answer detailsCorrect answersC, D
Single choice
Refer to the exhibit. ![]() A communication issue exists between hosts 192.168.0.11 and 34.253.101.190. What is a description of the initial TCP connection? Reveal answer details Close answer detailsCorrect answerD
Single choice
Refer to the exhibit. ![]() What is occurring in this network? Reveal answer details Close answer detailsCorrect answerA
Single choice
Refer to the exhibit. ![]() A SOC team member receives a case from his colleague with notes attached. The artifacts and alerts associated with the case must be analyzed and a conclusion must be provided. What is the cause of the alert? Reveal answer details Close answer detailsCorrect answerC
Single choice
Which option describes indicators of attack? Reveal answer details Close answer detailsCorrect answerD Explanation Indicators of attack (IoAs) are signs that an attack may be in progress or imminent. Malware reinfection within a few minutes of removal (D) is a strong IoA because it suggests that the attacker has a persistent mechanism to redeploy malware, indicating an active compromise of the system.
Single choice
What is vulnerability management? Reveal answer details Close answer detailsCorrect answerC Explanation References:
Single choice
What is the principle of defense-in-depth? Reveal answer details Close answer detailsCorrect answerB
Single choice
Refer to the exhibit. ![]() What is the potential threat identified in this Stealthwatch dashboard? Reveal answer details Close answer detailsCorrect answerC
Single choice
Which metric in CVSS indicates an attack that takes a destination bank account number and replaces it with a different bank account number? Reveal answer details Close answer detailsCorrect answerD
Single choice
What describes the framework that enables to control user access to critical information in the heterogenous technology environments? Reveal answer details Close answer detailsCorrect answerD
Single choice
Which action matches the weaponization step of the Cyber Kill Chain model? Reveal answer details Close answer detailsCorrect answerB
Single choice
Which identifier is used in Linux systems to uniquely identify a running process? Reveal answer details Close answer detailsCorrect answerC Explanation A Process ID (PID) is a unique identifier assigned by the operating system to each running process in a Linux system. It allows the system and administrators to manage processes, including monitoring, controlling, and terminating them. UID (A) identifies users, while GID (B) identifies groups. SID (D) is typically associated with Windows security identifiers. PIDs are essential for system administration and security analysis because they help track process behavior and resource usage. For example, analysts can use commands like ps or top to view active processes and their PIDs. Suspicious processes can be identified by unusual names, resource consumption, or parent-child relationships. Understanding PIDs is also important in incident response, as it enables analysts to trace malicious activity back to its source process.
Single choice
Developers must implement tasks on remote Windows environments. They decided to use scripts for enterprise applications through PowerShell. Why does the functionality not work? Reveal answer details Close answer detailsCorrect answerD
Single choice
What is the difference between the rule-based detection when compared to behavioral detection? Reveal answer details Close answer detailsCorrect answerB Explanation Rule-based detection involves identifying malicious activities based on predefined rules or patterns of known attacks; it does not adapt or change with new data. In contrast, behavioral detection adapts over
Multiple choice
What are the two differences between stateful and deep packet inspection? (Choose two ) Reveal answer details Close answer detailsCorrect answersA, B Explanation A: Stateful inspection tracks the state of network connections, such as TCP streams, to determine if a packet is part of an established connection.
Single choice
While viewing packet capture data, an analyst sees that one IP is sending and receiving traffic for multiple devices by modifying the IP header. Which technology makes this behavior possible? Reveal answer details Close answer detailsCorrect answerD Explanation Network address translation (NAT) is a method of mapping an IP address space into another by modifying network address information in the IP header of packets while they are in transit across a traffic routing device.
Single choice
What is indicated by an increase in IPv4 traffic carrying protocol 41 ? Reveal answer details Close answer detailsCorrect answerD
Single choice
What is a difference between an inline and a tap mode traffic monitoring? Reveal answer details Close answer detailsCorrect answerD Explanation References:
Single choice
Which of these describes SOC metrics in relation to security incidents? Reveal answer details Close answer detailsCorrect answerA
Single choice
Which regex matches only on all lowercase letters? Reveal answer details Close answer detailsCorrect answerA
Single choice
Refer to the exhibit. ![]() What type of event is occurring? Reveal answer details Close answer detailsCorrect answerD
Single choice
What is a collection of compromised machines that attackers use to carry out a DDoS attack? Reveal answer details Close answer detailsCorrect answerB
Single choice
Refer to the exhibit. ![]() What must be interpreted from this packet capture? Reveal answer details Close answer detailsCorrect answerC Explanation The packet capture shows that IP address 192.168.88.149, using source port 80 (common for HTTP traffic), initiated communication with IP address 192.168.88.12 at destination port 49098, using the TCP protocol, indicating a typical client-server interaction over the web.
Single choice
What is the benefit of processing statistical data for security systems? Reveal answer details Close answer detailsCorrect answerA
Single choice
Which management concept best describes developing, operating, maintaining, upgrading, and disposing of all resources? Reveal answer details Close answer detailsCorrect answerC
Drag & drop
DRAG DROP ![]() Refer to the exhibit. Drag and drop the element name from the left onto the correct piece of the PCAP file on the right. ![]() Reveal answer details Close answer details![]()
Single choice
Refer to the exhibit ![]() Which TLS version does this client support? Reveal answer details Close answer detailsCorrect answerB
Single choice
How is SQL injection prevented? Reveal answer details Close answer detailsCorrect answerA
Single choice
An analyst is using the SIEM platform and must extract a custom property from a Cisco device and capture the phrase, "File: Clean." Which regex must the analyst import? Reveal answer details Close answer detailsCorrect answerA Explanation A regular expression (regex) is a sequence of characters that defines a search pattern for text. A regex can be used to extract custom properties from log messages or events in a SIEM platform. In this case, the regex that matches the phrase "File: Clean" exactly is ^File: Clean$. The ^ symbol indicates the beginning of the line and the $ symbol indicates the end of the line. The regex ensures that no other characters are before or after the phrase.
Single choice
What is a difference between tampered and untampered disk images? Reveal answer details Close answer detailsCorrect answerD Explanation The disk image must be intact for forensics analysis. As a cybersecurity professional, you may be given the task of capturing an image of a disk in a forensic manner. Imagine a security incident has occurred on a system and you are required to perform some forensic investigation to determine who and what caused the attack. Additionally, you want to ensure the data that was captured is not tampered with or modified during the creation of a disk image process. Ref: Cisco Certified CyberOps Associate 200-201 Certification Guide
Single choice
What is the difference between a threat and an exploit? Reveal answer details Close answer detailsCorrect answerC
Single choice
Which of these is a defense-in-depth strategy principle? Reveal answer details Close answer detailsCorrect answerB
Multiple choice
What are two social engineering techniques? (Choose two.) Reveal answer details Close answer detailsCorrect answersC, E Explanation Social engineering techniques often involve manipulating individuals into divulging confidential information or performing actions that compromise security. Phishing involves sending fraudulent messages (often emails) that appear to be from reputable sources with the goal of stealing sensitive data or installing malware. Pharming redirects the traffic of a legitimate website to another fraudulent website without the user's knowledge, aiming to collect the user's credentials.
Single choice
What are the three critical security principles or goals of the CIA triad? Reveal answer details Close answer detailsCorrect answerA
Single choice
Refer to the exhibit. ![]() An employee received an email from an unknown sender with an attachment and reported it as a phishing attempt. An engineer uploaded the file to Cuckoo for further analysis. What should an engineer interpret from the provided Cuckoo report? Reveal answer details Close answer detailsCorrect answerA Explanation The Cuckoo report provides information on the behavior of the file submitted for analysis, and the fact that it was identified as Win32.polip.a.exe indicates that it is an executable file and may pose a risk. The description of the file as "malicious" suggests that it may contain malicious code or perform unwanted actions. It is important to note that just because a file has a specific name or label, it does not necessarily mean it is definitely malicious. Further analysis and investigation would be necessary to fully assess the risk posed by the file. However, based on the information provided in the report, it is reasonable to flag the file as malicious and take appropriate action to protect the system and data.
Single choice
Refer to the exhibit. ![]() Which packet contains a file that is extractable within Wireshark? Reveal answer details Close answer detailsCorrect answerD
Single choice
Refer to the exhibit. ![]() What should be interpreted from this packet capture? Reveal answer details Close answer detailsCorrect answerC
Single choice
One of the objectives of information security is to protect the CIA of information and systems. What does CIA mean in this context? Reveal answer details Close answer detailsCorrect answerD
Single choice
A company is using several network applications that require high availability and responsiveness, such that milliseconds of latency on network traffic is not acceptable. An engineer needs to analyze the network and identify ways to improve traffic movement to minimize delays. Which information must the engineer obtain for this analysis? Reveal answer details Close answer detailsCorrect answerA Explanation For high availability and responsiveness, especially where milliseconds of latency are critical, an engineer must analyze the network's performance in detail. Total throughput on the interface of the router will provide information on the bandwidth and traffic load, which is essential for understanding if the network can handle the current and projected traffic without delays. NetFlow records are crucial for this analysis as they provide data about the traffic flow across the network, which helps in identifying patterns, peak usage times, and types of traffic. This information is vital for making informed decisions to optimize traffic movement and minimize latency.
Single choice
What is the impact of false positive alerts on business compared to true positive? Reveal answer details Close answer detailsCorrect answerD Explanation The log in the exhibit is generated by a firewall. It shows a deny action taken on TCP traffic, specifying the source and destination addresses and ports, which is characteristic of firewall logs. Firewalls are designed to control incoming and outgoing network traffic based on predetermined security rules, and this log entry reflects the enforcement of such a rule.
Single choice
![]() Refer to the exhibit. What is occurring in this network traffic? Reveal answer details Close answer detailsCorrect answerC |