200-201 Exam Details

  • Exam Code
    :200-201
  • Exam Name
    :Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS)
  • Certification
    :CyberOps Associate
  • Vendor
    :Cisco
  • Total Questions
    :543 Q&As
  • Last Updated
    :May 24, 2026

Cisco 200-201 Online Questions & Answers

  • Question 141:

    What is the name of the technology that searches for and reports on known weaknesses and flaws present in an organization's IT infrastructure?

    A. vulnerability scanner
    B. identity and access management
    C. configuration management
    D. mobile device management

  • Question 142:

    A SOC analyst detected connections to known C&C and port scanning activity to main HR database servers from one of the HR endpoints, via Cisco StealthWatch.

    What are the two next steps of the SOC team according to the NIST.SP800- 61 incident handling process? (Choose two.)

    A. Update antivirus signature databases on affected endpoints to block connections to C&C.
    B. Isolate affected endpoints and take disk images for analysis.
    C. Block connection to this C&C server on the perimeter next-generation firewall.
    D. Provide security awareness training to HR managers and employees
    E. Detect the attack vector and analyze C&C connections.

  • Question 143:

    What are two denial of service attacks? (Choose two.)

    A. MITM
    B. TCP connections
    C. ping of death
    D. UDP flooding
    E. code red

  • Question 144:

    Refer to the exhibit. A security engineer receives several alerts from the SNORT IPS/IDS reporting malicious traffic.

    What should the engineer understand by examining the SNORT logs?

    A. A remote threat performs an EternalBlue attack on a Windows system on several ports.
    B. An inside threat performs an EternalBlue attack on hosts 192.168.2.101 and 192.168.200.10 on port 445.
    C. A remote threat performs an EternalBlue attack on several hosts and different ports.
    D. An inside threat performs an EternalBlue attack on a Windows system on port 445.

  • Question 145:

    Which scenario describes a social engineering attack?

    A. Malicious insider trying to gather information on company security
    B. Text message pretending to be from a legitimate company with a malicious URL inside
    C. Suspicious file detected on a workstation
    D. Company with a recent data breach where confidential information was stolen

  • Question 146:

    Which action matches the weaponization step of the Cyber Kill Chain Model?

    A. Develop a specific malware to exploit a vulnerable server.
    B. Construct a trojan and deliver it to the victim.
    C. Match a known script to a vulnerability.
    D. Scan open services and ports on a server.

  • Question 147:

    Syslog collecting software is installed on the server For the log containment, a disk with FAT type partition is used An engineer determined that log files are being corrupted when the 4 GB tile size is exceeded.

    Which action resolves the issue?

    A. Add space to the existing partition and lower the retention penod.
    B. Use FAT32 to exceed the limit of 4 GB.
    C. Use the Ext4 partition because it can hold files up to 16 TB.
    D. Use NTFS partition for log file containment

  • Question 148:

    Refer to the exhibit.

    What is the potential threat identified in this Stealthwatch dashboard?

    A. Host 10.201.3.149 is sending data to 152.46.6.91 using TCP/443.
    B. Host 152.46.6.91 is being identified as a watchlist country for data transfer.
    C. Traffic to 152.46.6.149 is being denied by an Advanced Network Control policy.
    D. Host 10.201.3.149 is receiving almost 19 times more data than is being sent to host 152.46.6.91.

  • Question 149:

    Refer to the exhibit.

    An engineer is analyzing a PCAP file after a recent breach An engineer identified that the attacker used an aggressive ARP scan to scan the hosts and found web and SSH servers. Further analysis showed several SSH Server Banner and Key Exchange Initiations. The engineer cannot see the exact data being transmitted over an encrypted channel and cannot identify how the attacker gained access.

    How did the attacker gain access?

    A. by using the buffer overflow in the URL catcher feature for SSH
    B. by using an SSH Tectia Server vulnerability to enable host-based authentication
    C. by using an SSH vulnerability to silently redirect connections to the local host
    D. by using brute force on the SSH service to gain access

  • Question 150:

    According to the NIST SP 800-86.

    which two types of data are considered volatile? (Choose two.)

    A. swap files
    B. temporary files
    C. login sessions
    D. dump files
    E. free space

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 200-201 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.