Exam Details

  • Exam Code
    :200-201
  • Exam Name
    :Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS)
  • Certification
    :CyberOps Associate
  • Vendor
    :Cisco
  • Total Questions
    :406 Q&As
  • Last Updated
    :Apr 23, 2024

Cisco CyberOps Associate 200-201 Questions & Answers

  • Question 21:

    Refer to the exhibit.

    What is the potential threat identified in this Stealthwatch dashboard?

    A. A policy violation is active for host 10.10.101.24.

    B. A host on the network is sending a DDoS attack to another inside host.

    C. There are three active data exfiltration alerts.

    D. A policy violation is active for host 10.201.3.149.

  • Question 22:

    What is a difference between data obtained from Tap and SPAN ports?

    A. Tap mirrors existing traffic from specified ports, while SPAN presents more structured data for deeper analysis.

    B. SPAN passively splits traffic between a network device and the network without altering it, while Tap alters response times.

    C. SPAN improves the detection of media errors, while Tap provides direct access to traffic with lowered data visibility.

    D. Tap sends traffic from physical layers to the monitoring device, while SPAN provides a copy of network traffic from switch to destination

  • Question 23:

    Which metric is used to capture the level of access needed to launch a successful attack?

    A. privileges required

    B. user interaction

    C. attack complexity

    D. attack vector

  • Question 24:

    What is a difference between tampered and untampered disk images?

    A. Tampered images have the same stored and computed hash.

    B. Tampered images are used as evidence.

    C. Untampered images are used for forensic investigations.

    D. Untampered images are deliberately altered to preserve as evidence

  • Question 25:

    Which evasion technique is indicated when an intrusion detection system begins receiving an abnormally high volume of scanning from numerous sources?

    A. resource exhaustion

    B. tunneling

    C. traffic fragmentation

    D. timing attack

  • Question 26:

    A security engineer deploys an enterprise-wide host/endpoint technology for all of the company's corporate PCs. Management requests the engineer to block a selected set of applications on all PCs.

    Which technology should be used to accomplish this task?

    A. application whitelisting/blacklisting

    B. network NGFW

    C. host-based IDS

    D. antivirus/antispyware software

  • Question 27:

    Which event is a vishing attack?

    A. obtaining disposed documents from an organization

    B. using a vulnerability scanner on a corporate network

    C. setting up a rogue access point near a public hotspot

    D. impersonating a tech support agent during a phone call

  • Question 28:

    Which two elements of the incident response process are stated in NIST Special Publication 800-61 r2? (Choose two.)

    A. detection and analysis

    B. post-incident activity

    C. vulnerability management

    D. risk assessment

    E. vulnerability scoring

  • Question 29:

    Which filter allows an engineer to filter traffic in Wireshark to further analyze the PCAP file by only showing the traffic for LAN 10.11.x.x, between workstations and servers without the Internet?

    A. src=10.11.0.0/16 and dst=10.11.0.0/16

    B. ip.src==10.11.0.0/16 and ip.dst==10.11.0.0/16

    C. ip.src=10.11.0.0/16 and ip.dst=10.11.0.0/16

    D. src==10.11.0.0/16 and dst==10.11.0.0/16

  • Question 30:

    Which attack represents the evasion technique of resource exhaustion?

    A. SQL injection

    B. man-in-the-middle

    C. bluesnarfing

    D. denial-of-service

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 200-201 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.