200-201 Exam Details

  • Exam Code
    :200-201
  • Exam Name
    :Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS)
  • Certification
    :CyberOps Associate
  • Vendor
    :Cisco
  • Total Questions
    :543 Q&As
  • Last Updated
    :May 24, 2026

Cisco 200-201 Online Questions & Answers

  • Question 391:

    Which data capture includes payload and header information?

    A. frame check sequence
    B. full packet
    C. alert data
    D. session logs

  • Question 392:

    Which attack involves redirecting users to a malicious website without their knowledge?

    A. phishing
    B. pharming
    C. spoofing
    D. sniffing

  • Question 393:

    A security analyst notices a sudden surge of incoming traffic and detects unknown packets from unknown senders After further investigation, the analyst learns that customers claim that they cannot access company servers According to NIST SP800-61, in which phase of the incident response process is the analyst?

    A. post-incident activity
    B. detection and analysis
    C. preparation
    D. containment, eradication, and recovery

  • Question 394:

    What are two differences between tampered disk images and untampered disk images? (Choose two.)

    A. The image is tampered if the stored hash and the computed hash are identical.
    B. Tampered images are used as an element for the root cause analysis report.
    C. Untampered images can be used as law enforcement evidence.
    D. Tampered images are used in a security Investigation process.
    E. The image is untampered if the existing stored hash matches the computed one.

  • Question 395:

    Refer to the exhibit.

    Which event is occurring?

    A. A binary named "submit" is running on VM cuckoo1.
    B. A binary is being submitted to run on VM cuckoo1
    C. A binary on VM cuckoo1 is being submitted for evaluation
    D. A URL is being evaluated to see if it has a malicious binary

  • Question 396:

    Which difficulty occurs when log messages are compared from two devices separated by a Layer 3 device that performs Network Address Translation?

    A. IP addresses in the log messages match
    B. Timestamps of the log messages are different.
    C. Log messages contain incorrect information
    D. IP addresses in the log messages do not match

  • Question 397:

    An analyst received a ticket about degraded processing capability for one of the HR department's servers. On the same day, an engineer noticed disabled antivirus software and could not determine when or why it occurred.

    According to the NIST Incident Handling Guide, what is the next phase of this investigation?

    A. Detection
    B. Analysis
    C. Eradication
    D. Recovery

  • Question 398:

    Why should an engineer use a full packet capture to investigate a security breach?

    A. It provides the full TCP streams for the engineer to follow the metadata to identify the incoming threat.
    B. It collects metadata for the engineer to analyze, including IP traffic packet data that is sorted, parsed, and indexed.
    C. It reconstructs the event allowing the engineer to identify the root cause by seeing what took place during the breach.
    D. It captures the TCP flags set within each packet for the engineer to focus on suspicious packets to identify malicious activity.

  • Question 399:

    Refer to the exhibit.

    What is depicted in the exhibit?

    A. Windows Event logs
    B. Apache logs
    C. IIS logs
    D. UNIX-based syslog

  • Question 400:

    Which type of access control depends on the job function of the user?

    A. discretionary access control
    B. nondiscretionary access control
    C. role-based access control
    D. rule-based access control

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 200-201 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.