200-201 Exam Details

  • Exam Code
    :200-201
  • Exam Name
    :Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS)
  • Certification
    :CyberOps Associate
  • Vendor
    :Cisco
  • Total Questions
    :543 Q&As
  • Last Updated
    :Jun 01, 2026

Cisco 200-201 Online Questions & Answers

  • Question 351:

    DRAG DROP

    Drag and drop the security concept from the left onto the example of that concept on the right.

    Select and Place:

  • Question 352:

    What is the functionality of an IDS?

    A. forensic tool used to perform an in-depth analysis and debugging
    B. software or device which monitors and identifies malicious network activity
    C. device or software that detects and blocks suspicious files
    D. endpoint protection software that prevents viruses and malware

  • Question 353:

    Which HTTP header field is used in forensics to identify the type of browser used?

    A. referrer
    B. host
    C. user-agent
    D. accept-language

  • Question 354:

    Which two protocols are used for DDoS amplification attacks? (Choose two.)

    A. HTTP
    B. DNS
    C. TCP
    D. ICMPv6
    E. NTP

  • Question 355:

    An engineer is working on a ticket for an incident from the incident management team. A week ago, an external web application was targeted by a DDoS attack. Server resources were exhausted and after two hours, it crashed. An engineer was able to identify the attacker and technique used. Three hours after the attack, the server was restored and the engineer recommended implementing mitigation by Blackhole filtering and transferred the incident ticket back to the IR team.

    According to NIST.SP800-61, at which phase of the incident response did the engineer finish work?

    A. post-incident activity
    B. preparation
    C. detection and analysis
    D. containment, eradication, and recovery

  • Question 356:

    Which data format is the most efficient to build a baseline of traffic seen over an extended period of time?

    A. syslog messages
    B. full packet capture
    C. NetFlow
    D. firewall event logs

  • Question 357:

    What describes the concept of data consistently and readily being accessible for legitimate users?

    A. integrity
    B. availability
    C. accessibility
    D. confidentiality

  • Question 358:

    Refer to the exhibit.

    What type of event is occurring?

    A. Legitimate web browsing activity
    B. Distributed Denial of Service (DDoS) attack
    C. User trying to access a file share
    D. Malware attempting to spread laterally

  • Question 359:

    Refer to the exhibit.

    Which field contains DNS header information if the payload is a query or response?

    A. ID
    B. Z
    C. QR
    D. TC

  • Question 360:

    Which of these is a defense-in-depth strategy principle?

    A. Identify the minimum resource required per employee.
    B. Provide the minimum permissions needed to perform job functions.
    C. Disable administrative accounts to avoid unauthorized changes.
    D. Assign the least network privileges to segment network permissions.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 200-201 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.