200-201 Exam Details

  • Exam Code
    :200-201
  • Exam Name
    :Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS)
  • Certification
    :CyberOps Associate
  • Vendor
    :Cisco
  • Total Questions
    :543 Q&As
  • Last Updated
    :May 24, 2026

Cisco 200-201 Online Questions & Answers

  • Question 381:

    What is the purpose of hashing in data integrity verification?

    A. to encrypt data
    B. to compress data
    C. to generate a unique digest
    D. to transmit data securely

  • Question 382:

    A SOC analyst is investigating an incident that involves a Linux system that is identifying specific sessions.

    Which identifier tracks an active program?

    A. application identification number
    B. active process identification number
    C. runtime identification number
    D. process identification number

  • Question 383:

    Which attack is the network vulnerable to when a stream cipher like RC4 is used twice with the same key?

    A. forgery attack
    B. plaintext-only attack
    C. ciphertext-only attack
    D. meet-in-the-middle attack

  • Question 384:

    A security expert is working on a copy of the evidence, an ISO file that is saved in CDFS format.

    Which type of evidence is this file?

    A. CD data copy prepared in Windows
    B. CD data copy prepared in Mac-based system
    C. CD data copy prepared in Linux system
    D. CD data copy prepared in Android-based system

  • Question 385:

    An analyst is investigating a host in the network that appears to be communicating to a command and control server on the Internet. After collecting this packet capture, the analyst cannot determine the technique and payload used for the communication.

    Which obfuscation technique is the attacker using?

    A. Base64 encoding
    B. TLS encryption
    C. SHA-256 hashing
    D. ROT13 encryption

  • Question 386:

    After a large influx of network traffic to externally facing devices, a security engineer begins investigating what appears to be a denial of service attack. When the packet capture data is reviewed, the engineer notices that the traffic is a single SYN packet to each port.

    Which type of attack is occurring?

    A. traffic fragmentation
    B. port scanning
    C. host profiling
    D. SYN flood

  • Question 387:

    Which incidence response step includes identifying all hosts affected by an attack?

    A. detection and analysis
    B. post-incident activity
    C. preparation
    D. containment, eradication, and recovery

  • Question 388:

    DRAG DROP

    Refer to the exhibit.

    Drag and drop the element names from the left onto the corresponding pieces of the PCAP file on the right.

    Select and Place:

  • Question 389:

    How is attacking a vulnerability categorized?

    A. action on objectives
    B. delivery
    C. exploitation
    D. installation

  • Question 390:

    Which signature impacts network traffic by causing legitimate traffic to be blocked?

    A. false negative
    B. true positive
    C. true negative
    D. false positive

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 200-201 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.