Exam Details

  • Exam Code
    :200-201
  • Exam Name
    :Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS)
  • Certification
    :CyberOps Associate
  • Vendor
    :Cisco
  • Total Questions
    :406 Q&As
  • Last Updated
    :Apr 23, 2024

Cisco CyberOps Associate 200-201 Questions & Answers

  • Question 11:

    Which information must an organization use to understand the threats currently targeting the organization?

    A. threat intelligence

    B. risk scores

    C. vendor suggestions

    D. vulnerability exposure

  • Question 12:

    A security specialist notices 100 HTTP GET and POST requests for multiple pages on the web servers. The agent in the requests contains PHP code that, if executed, creates and writes to a new PHP file on the webserver. Which event category is described?

    A. reconnaissance

    B. action on objectives

    C. installation

    D. exploitation

  • Question 13:

    Refer to the exhibit.

    Which field contains DNS header information if the payload is a query or a response?

    A. Z

    B. ID

    C. TC

    D. QR

  • Question 14:

    What is a difference between SOAR and SIEM?

    A. SOAR platforms are used for threat and vulnerability management, but SIEM applications are not

    B. SIEM applications are used for threat and vulnerability management, but SOAR platforms are not

    C. SOAR receives information from a single platform and delivers it to a SIEM

    D. SIEM receives information from a single platform and delivers it to a SOAR

  • Question 15:

    An analyst discovers that a legitimate security alert has been dismissed. Which signature caused this impact on network traffic?

    A. true negative

    B. false negative

    C. false positive

    D. true positive

  • Question 16:

    During which phase of the forensic process are tools and techniques used to extract information from the collected data?

    A. investigation

    B. examination

    C. reporting

    D. collection

  • Question 17:

    Which step in the incident response process researches an attacking host through logs in a SIEM?

    A. detection and analysis

    B. preparation

    C. eradication

    D. containment

  • Question 18:

    What is a purpose of a vulnerability management framework?

    A. identifies, removes, and mitigates system vulnerabilities

    B. detects and removes vulnerabilities in source code

    C. conducts vulnerability scans on the network

    D. manages a list of reported vulnerabilities

  • Question 19:

    An analyst is using the SIEM platform and must extract a custom property from a Cisco device and capture the phrase, "File: Clean." Which regex must the analyst import?

    A. File: Clean

    B. ^Parent File Clean$

    C. File: Clean (.*)

    D. ^File: Clean$

  • Question 20:

    How does an attacker observe network traffic exchanged between two users?

    A. port scanning

    B. man-in-the-middle

    C. command injection

    D. denial of service

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 200-201 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.