Cisco

200-201 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 290-question bank.

Provider
Cisco
Question bank
290
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for 200-201, a certification listed under Cisco. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Cisco. The certification credential is issued by Cisco, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Which event is user interaction?

    Choose one answer.

    • gaining root access
    • executing remote code
    • reading and writing file permission
    • opening a malicious file
  2. Question 2 · 1

    An analyst is investigating an incident in a SOC environment. Which method is used to identify a session from a group of logs?

    Choose one answer.

    • sequence numbers
    • IP identifier
    • 5-tuple
    • timestamps
  3. Question 3 · 1

    Which system monitors local system operation and local network access for violations of a security policy?

    Choose one answer.

    • host-based intrusion detection
    • systems-based sandboxing
    • host-based firewall
    • antivirus
  4. Question 4 · 1

    An analyst received an alert on their desktop computer showing that an attack was successful on the host. After investigating, the analyst discovered that no mitigation action occurred during the attack. What is the reason for this discrepancy?

    Choose one answer.

    • The computer has a HIPS installed on it.
    • The computer has a NIPS installed on it.
    • The computer has a HIDS installed on it.
    • The computer has a NIDS installed on it.
  5. Question 5 · 1

    Refer to the exhibit. What is the potential threat identified in this Stealthwatch dashboard?

    Choose one answer.

    Question illustration 1
    • A policy violation is active for host 10.10.101.24.
    • A host on the network is sending a DDoS attack to another inside host.
    • There are three active data exfiltration alerts.
    • A policy violation is active for host 10.201.3.149.
  6. Question 6 · 1

    What is a difference between tampered and untampered disk images?

    Choose one answer.

    • Tampered images have the same stored and computed hash.
    • Untampered images are deliberately altered to preserve as evidence.
    • Tampered images are used as evidence.
    • Untampered images are used for forensic investigations.
  7. Question 7 · 1

    What is a sandbox interprocess communication service?

    Choose one answer.

    • A collection of rules within the sandbox that prevent the communication between sandboxes.
    • A collection of network services that are activated on an interface, allowing for inter-port communication.
    • A collection of interfaces that allow for coordination of activities among processes.
    • A collection of host services that allow for communication between sandboxes.
  8. Question 8 · 1

    An analyst is investigating a host in the network that appears to be communicating to a command and control server on the Internet. After collecting this packet capture, the analyst cannot determine the technique and payload used for the communication. Which obfuscation technique is the attacker using?

    Choose one answer.

    Question illustration 1
    • Base64 encoding
    • transport layer security encryption
    • SHA-256 hashing
    • ROT13 encryption
  9. Question 9 · 1

    During which phase of the forensic process is data that is related to a specific event labeled and recorded to preserve its integrity?

    Choose one answer.

    • examination
    • investigation
    • collection
    • reporting
  10. Question 10 · 1

    Which step in the incident response process researches an attacking host through logs in a SIEM?

    Choose one answer.

    • detection and analysis
    • preparation
    • eradication
    • containment
  11. Question 11 · 1

    A malicious file has been identified in a sandbox analysis tool. Which piece of information is needed to search for additional downloads of this file by other hosts?

    Choose one answer.

    • file type
    • file size
    • file name
    • file hash value
  12. Question 12 · 1

    What is a difference between SOAR and SIEM?

    Choose one answer.

    • SOAR platforms are used for threat and vulnerability management, but SIEM applications are not
    • SIEM applications are used for threat and vulnerability management, but SOAR platforms are not
    • SOAR receives information from a single platform and delivers it to a SIEM
    • SIEM receives information from a single platform and delivers it to a SOAR
  13. Question 13 · 1

    Refer to the exhibit. What is the potential threat identified in this Stealthwatch dashboard?

    Choose one answer.

    Question illustration 1
    • Host 10.201.3.149 is sending data to 152.46.6.91 using TCP/443.
    • Host 152.46.6.91 is being identified as a watchlist country for data transfer.
    • Traffic to 152.46.6.149 is being denied by an Advanced Network Control policy.
    • Host 10.201.3.149 is receiving almost 19 times more data than is being sent to host 152.46.6.91.
  14. Question 14 · 1

    Refer to the exhibit. What is the potential threat identified in this Stealthwatch dashboard?

    Choose one answer.

    Question illustration 1
    • A policy violation is active for host 10.10.101.24.
    • A host on the network is sending a DDoS attack to another inside host.
    • There are two active data exfiltration alerts.
    • A policy violation is active for host 10.201.3.149.
  15. Question 15 · 1

    Which security technology allows only a set of pre-approved applications to run on a system?

    Choose one answer.

    • application-level blacklisting
    • host-based IPS
    • application-level whitelisting
    • antivirus

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free