200-201 Exam Details

  • Exam Code
    :200-201
  • Exam Name
    :Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS)
  • Certification
    :CyberOps Associate
  • Vendor
    :Cisco
  • Total Questions
    :543 Q&As
  • Last Updated
    :May 24, 2026

Cisco 200-201 Online Questions & Answers

  • Question 101:

    Which concept describes the total number of points where an attacker can attempt to enter or extract data from a system?

    A. attack vector
    B. vulnerability
    C. attack surface
    D. threat actor

  • Question 102:

    What is the function of a command and control server?

    A. It enumerates open ports on a network device
    B. It drops secondary payload into malware
    C. It is used to regain control of the network after a compromise
    D. It sends instruction to a compromised system

  • Question 103:

    An analyst received a ticket regarding a degraded processing capability for one of the HR department's servers. On the same day, an engineer noticed a disabled antivirus software and was not able to determine when or why it occurred.

    According to the NIST Incident Handling Guide, what is the next phase of this investigation?

    A. Recovery
    B. Detection
    C. Eradication
    D. Analysis

  • Question 104:

    What is an attack surface as compared to a vulnerability?

    A. any potential danger to an asset
    B. the sum of all paths for data into and out of the environment
    C. an exploitable weakness in a system or its design
    D. the individuals who perform an attack

  • Question 105:

    What is the difference between discretionary access control (DAC) and role-based access control (RBAC)?

    A. DAC requires explicit authorization for a given user on a given object, and RBAC requires specific conditions.
    B. RBAC access is granted when a user meets specific conditions, and in DAC, permissions are applied on user and group levels.
    C. RBAC is an extended version of DAC where you can add an extra level of authorization based on time.
    D. DAC administrators pass privileges to users and groups, and in RBAC, permissions are applied to specific groups

  • Question 106:

    An engineer is analyzing a recent breach where confidential documents were altered and stolen by the receptionist Further analysis shows that the threat actor connected an externa USB device to bypass security restrictions and steal data

    The engineer could not find an external USB device.

    Which piece of information must an engineer use for attribution in an investigation?

    A. list of security restrictions and privileges boundaries bypassed
    B. external USB device
    C. receptionist and the actions performed
    D. stolen data and its criticality assessment

  • Question 107:

    Which vulnerability allows attackers to execute arbitrary code by overwriting memory?

    A. SQL injection
    B. cross-site scripting
    C. buffer overflow
    D. phishing

  • Question 108:

    Which two elements of the incident response process are stated in NIST SP 800-61 r2? (Choose two.)

    A. detection and analysis
    B. post-incident activity
    C. vulnerability scoring
    D. vulnerability management
    E. risk assessment

  • Question 109:

    Refer to exhibit.

    An analyst performs the analysis of the pcap file to detect the suspicious activity.

    What challenges did the analyst face in terms of data visibility?

    A. data encapsulation
    B. code obfuscation
    C. data encryption
    D. IP fragmentation

  • Question 110:

    An analyst discovers that a legitimate security alert has been dismissed.

    Which signature caused this impact on network traffic?

    A. true negative
    B. false negative
    C. false positive
    D. true positive

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 200-201 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.