200-201 Exam Details

  • Exam Code
    :200-201
  • Exam Name
    :Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS)
  • Certification
    :CyberOps Associate
  • Vendor
    :Cisco
  • Total Questions
    :543 Q&As
  • Last Updated
    :

Cisco 200-201 Online Questions & Answers

  • Question 231:

    Refer to the exhibit.

    Which type of log is displayed?

    A. IDS
    B. proxy
    C. NetFlow
    D. sys

  • Question 232:

    An engineer needs to fetch logs from a proxy server and generate actual events according to the data received.

    Which technology should the engineer use to accomplish this task?

    A. Firepower
    B. Email Security Appliance
    C. Web Security Appliance
    D. Stealthwatch

  • Question 233:

    An offline audit log contains the source IP address of a session suspected to have exploited a vulnerability resulting in system compromise.

    Which kind of evidence is this IP address?

    A. best evidence
    B. corroborative evidence
    C. indirect evidence
    D. forensic evidence

  • Question 234:

    Refer to the exhibit.

    An analyst receives an IDS alert pertaining to a possible data exfiltration attempt. An additional set of logs is collected from different systems and analyzed.

    Which type of evidence do the logs provide in relation to the primary alert from the IDS?

    A. corroborative evidence
    B. primary evidence
    C. circumstantial evidence
    D. secondary evidence

  • Question 235:

    Which of these describes volatile evidence?

    A. logs
    B. registers and cache
    C. disk and removable drives
    D. usernames

  • Question 236:

    What is the difference between inline traffic interrogation and traffic mirroring?

    A. Inline interrogation is less complex as traffic mirroring applies additional tags to data.
    B. Traffic mirroring copies the traffic rather than forwarding it directly to the analysis tools
    C. Inline replicates the traffic to preserve integrity rather than modifying packets before sending them to other analysis tools.
    D. Traffic mirroring results in faster traffic analysis and inline is considerably slower due to latency.

  • Question 237:

    Refer to the exhibit.

    What kind of activity occurs in the network?

    A. TCP reset attack
    B. DNS redirect attack
    C. DNS flood
    D. UDP flood

  • Question 238:

    Which statement describes threat hunting?

    A. It is an activity by an entity to deliberately bring down critical internal servers.
    B. It includes any activity that might go after competitors and adversaries to infiltrate their systems.
    C. It is a vulnerability assessment conducted by cyber professionals.
    D. It is a prevention activity to detect signs of intrusion, compromise, data theft, abnormalities, or malicious activity.

  • Question 239:

    Refer to the exhibit.

    What is occurring?

    A. DNS amplification attack
    B. Brute force attack
    C. ARP poisoning
    D. Denial of service

  • Question 240:

    How is NetFlow different from traffic mirroring?

    A. NetFlow collects metadata and traffic mirroring clones data.
    B. Traffic mirroring impacts switch performance and NetFlow does not.
    C. Traffic mirroring costs less to operate than NetFlow.
    D. NetFlow generates more data than traffic mirroring.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 200-201 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.