200-201 Exam Details

  • Exam Code
    :200-201
  • Exam Name
    :Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS)
  • Certification
    :CyberOps Associate
  • Vendor
    :Cisco
  • Total Questions
    :543 Q&As
  • Last Updated
    :May 24, 2026

Cisco 200-201 Online Questions & Answers

  • Question 191:

    A user received a malicious email attachment named "DS045-report1122345.exe" and executed it.

    In which step of the Cyber Kill Chain is this event?

    A. reconnaissance
    B. delivery
    C. weaponization
    D. installation

  • Question 192:

    What is indicated by an increase in IPv4 traffic carrying protocol 41 ?

    A. additional PPTP traffic due to Windows clients
    B. unauthorized peer-to-peer traffic
    C. deployment of a GRE network on top of an existing Layer 3 network
    D. attempts to tunnel IPv6 traffic through an IPv4 network

  • Question 193:

    An automotive company provides new types of engines and special brakes for rally sports cars. The company has a database of inventions and patents for their engines and technical information Customers can access the database through the company's website after they register and identify themselves.

    Which type of protected data is accessed by customers?

    A. IP data
    B. PII data
    C. PSI data
    D. PHI data

  • Question 194:

    A security incident occurred with the potential of impacting business services.

    Who performs the attack?

    A. malware author
    B. threat actor
    C. bug bounty hunter
    D. direct competitor

  • Question 195:

    A company is using several network applications that require high availability and responsiveness, such that milliseconds of latency on network traffic is not acceptable. An engineer needs to analyze the network and identify ways to improve traffic movement to minimize delays.

    Which information must the engineer obtain for this analysis?

    A. total throughput on the interface of the router and NetFlow records
    B. output of routing protocol authentication failures and ports used
    C. running processes on the applications and their total network usage
    D. deep packet captures of each application flow and duration

  • Question 196:

    An analyst performs traffic analysis to detect data exfiltration and identifies a high frequency of DNS requests in a small period of time.

    Which technology makes this behavior feasible?

    A. access control list
    B. NAT
    C. encryption
    D. tunneling

  • Question 197:

    Which security monitoring data type is associated with application server logs?

    A. transaction data
    B. statistical data
    C. session data
    D. alert data

  • Question 198:

    A network engineer informed a security team of a large amount of traffic and suspicious activity from an unknown source to the company DMZ server The security team reviewed the data and identified a potential DDoS attempt According to NIST, at which phase of incident response is the security team?

    A. containment and eradication
    B. preparation
    C. recovery
    D. detection and analysis

  • Question 199:

    Which two elements are assets in the role of attribution in an investigation? (Choose two.)

    A. context
    B. session
    C. laptop
    D. firewall logs
    E. threat actor

  • Question 200:

    What should a security analyst consider when comparing inline traffic interrogation with traffic tapping to determine which approach to use in the network?

    A. Tapping interrogation replicates signals to a separate port for analyzing traffic
    B. Tapping interrogations detect and block malicious traffic
    C. Inline interrogation enables viewing a copy of traffic to ensure traffic is in compliance with security policies
    D. Inline interrogation detects malicious traffic but does not block the traffic

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 200-201 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.