Cisco CyberOps Associate (CBROPS) 200-201 practice questions

239 free questions with answers and explanations.

Practice test
  1. 1.An organization is deploying a new application that processes highly sensitive customer data, including financial records and personal health information. The legal and compliance team has mandated that the data must remain confidential, even when stored at rest on servers and in backups. Which cryptographic state is specifically addressed by this requirement?Security Concepts
  2. 2.A security operations center (SOC) analyst observes a significant increase in outbound UDP traffic from a specific internal subnet to various external IP addresses on port 123 (NTP). The traffic volume is abnormally high, and the destination IPs are diverse and frequently changing. There are no legitimate internal services that would initiate such a high volume of outbound NTP requests. Which type of attack is most likely underway?Security Concepts
  3. 3.A security architect is designing a new cloud-based microservices application. To enhance security, each microservice will run in its own isolated container, and strict network policies will be applied to control communication between them. This approach aims to minimize the impact of a compromise on one service by preventing it from easily affecting others. Which security principle is primarily being applied here?Security Concepts
  4. 4.A security auditor is reviewing an organization's cloud infrastructure. The auditor discovers that several virtual machines (VMs) running critical services have public IP addresses and are directly exposed to the internet. Furthermore, the firewall rules for these VMs permit all incoming traffic on common ports, including HTTP, HTTPS, SSH, and RDP, from any source IP address. Which common security vulnerability does this scenario primarily represent?Security Concepts
  5. 5.Which of the following common attack vectors exploits vulnerabilities in web applications by injecting malicious scripts into content that is then delivered to other users?Security Concepts
  6. 6.An organization is migrating its on-premises applications to a public cloud environment. The security team is concerned about ensuring that the cloud resources (virtual machines, databases, storage accounts) are configured securely according to industry best practices and compliance requirements before they are deployed. Which security program element is most relevant to this proactive approach?Security Concepts
  7. 7.A company is implementing a new data classification policy. Sensitive customer data, if compromised, would result in severe financial penalties and reputational damage. According to common security principles, which classification level should this data receive?Security Concepts
  8. 8.A security team is implementing a vulnerability management program and needs to establish a systematic approach to identify and categorize vulnerabilities. They decide to use a publicly available, standardized system for naming and identifying vulnerabilities. Which system are they most likely to adopt?Vulnerability Management
  9. 9.A company is conducting a security assessment of its external-facing web applications. They discover that one application uses a default administrative password and has several unnecessary services running on its web server. Which of the following best describes the security principle being violated?Security Concepts
  10. 10.A security architect is designing a system that requires ensuring data not only remains confidential but also that its origin can be verified and that the sender cannot later deny having sent it. Which cryptographic primitive is essential for achieving both data origin authentication and non-repudiation?Security Concepts
  11. 11.A security analyst is performing a black-box penetration test against a client's external web application. During the reconnaissance phase, the analyst discovers several subdomains and public-facing IP addresses, but no direct access to source code or internal network diagrams. Which of the following best describes the perspective and information available to the analyst at this stage?Vulnerability Management
  12. 12.A security analyst is reviewing system logs on a Linux server and notices repetitive failed login attempts for a root user account originating from various external IP addresses within a short timeframe. Which type of attack is most likely underway?Security Monitoring
  13. 13.A large enterprise uses a centralized logging system to collect security events from all network devices and servers. A security analyst frequently reviews these logs to identify anomalies and potential threats. This practice is a core component of which security program element?Security Concepts
  14. 14.A security team is analyzing network traffic logs and observes a significant increase in connection attempts to a web server from a single source IP address, occurring rapidly over a short period. The connection attempts are incomplete, with the attacker sending only the initial SYN packet but never completing the three-way handshake. What type of Denial of Service (DoS) attack is this?Security Concepts
  15. 15.A security operations center (SOC) analyst is investigating an alert from an Intrusion Prevention System (IPS) indicating a potential buffer overflow attack. The IPS has successfully blocked the traffic. The analyst needs to determine if the attack attempt was indeed a buffer overflow and identify its source and target. What type of security monitoring concept is the IPS primarily demonstrating in this scenario?Security Concepts
  16. 16.A security analyst is investigating a series of alerts from a host-based intrusion detection system (HIDS) indicating 'Registry Key Modification: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'. The alerts show that a new entry has been added pointing to an executable in the C:\Users\Public\ directory. What is the most likely purpose of this registry modification?Security Monitoring
  17. 17.An organization is considering implementing a continuous vulnerability management program. Which of the following is a primary benefit of integrating threat intelligence feeds into their vulnerability management process?Vulnerability Management
  18. 18.A security engineer is configuring a new Intrusion Detection System (IDS) to monitor network traffic for malicious activity. The engineer decides to implement a rule that triggers an alert whenever a specific, known malicious payload signature is detected within any network packet. This approach is an example of which type of security monitoring concept?Security Concepts
  19. 19.A security analyst is investigating a potential data exfiltration incident. Network traffic analysis reveals large volumes of encrypted data being sent from an internal server to an external IP address over an unusual port (TCP 53000). The internal server's legitimate function does not involve outbound connections of this nature. Which network intrusion analysis technique is most critical for determining the content of the exfiltrated data?Security Monitoring
  20. 20.A security analyst is investigating a suspicious process on a Linux server. The process is running as 'nobody' (a low-privilege user) but is observed making outbound connections to various external IP addresses on high-numbered, ephemeral ports. There is no legitimate application configured to run as 'nobody' with this network behavior. Which type of malware is most likely responsible?Security Monitoring
  21. 21.A security analyst is investigating a series of alerts indicating that multiple internal hosts are attempting to connect to various external IP addresses on non-standard ports. The traffic patterns are sporadic and do not align with known business operations. Further investigation reveals that these internal hosts are also communicating with each other over unusual ports. What type of attack framework is most likely indicated by these observations?Security Concepts
  22. 22.A company is conducting a privacy impact assessment (PIA) for a new cloud service that will store customer data. The assessment highlights that the cloud provider's terms of service allow data to be processed in multiple countries, some of which do not have equivalent data protection laws to the EU's GDPR. Which aspect of security laws and regulations is primarily at risk?Security Concepts
  23. 23.A financial institution is developing a new mobile banking application. The security team insists that all sensitive data stored on the mobile device must be protected even if the device is lost or stolen. Which endpoint security concept is critical to implement for this requirement?Security Concepts
  24. 24.A security operations center (SOC) analyst observes a series of suspicious events originating from an internal server: multiple failed login attempts to an external SSH server, followed by a successful connection, and then a large outbound data transfer to an unknown IP address. The analyst suspects command and control (C2) communication. Which port is most commonly associated with SSH, and thus a strong indicator in this C2 scenario?Security Concepts
  25. 25.A security analyst is configuring a SIEM to ingest logs from various network devices. The analyst needs to ensure that the SIEM can accurately parse and normalize logs from a new Cisco ASA firewall, which uses syslog for event reporting. Which of the following is the most critical step to ensure effective security monitoring from this new log source?Security Monitoring
  26. 26.A security architect is designing a system that requires ensuring data not only remains confidential and its integrity is preserved, but also that the sender of the data cannot later deny having sent it. Which cryptographic principle is specifically addressed by the requirement that the sender cannot deny sending the data?Security Concepts
  27. 27.A security analyst is investigating a series of anomalies on a web server. The server logs show numerous HTTP POST requests to a login page with varying usernames and passwords, originating from a single IP address over a short period. Many of these attempts are failing due to incorrect credentials. Which common attack vector is most likely being observed?Security Concepts
  28. 28.A cybersecurity firm is developing a new intrusion detection system (IDS) that uses a database of known attack patterns to identify malicious network traffic. This IDS is designed to flag traffic only when it precisely matches an entry in its database. Which detection method is primarily being employed?Security Concepts
  29. 29.A security operations center (SOC) analyst is reviewing alerts from the SIEM. One alert indicates 'Multiple failed attempts to access a critical database using SQL queries containing 'UNION SELECT' and 'pg_sleep()'. The source IP is from an external, untrusted network. Which vulnerability is the attacker most likely attempting to exploit?Security Monitoring
  30. 30.A security team is implementing a new access control system. The policy dictates that users should only have the minimum necessary access rights to perform their job functions, and these rights should be revoked automatically when their role changes or they leave the company. Which security principle is being enforced by this policy?Security Concepts
  31. 31.A security auditor is reviewing an organization's access control policies. The auditor notes that a database administrator has full read and write access to all customer data, including highly sensitive financial records, even though their daily tasks only require access to a subset of non-financial customer data. Which security principle is being violated?Security Concepts
  32. 32.A security analyst is investigating a series of alerts indicating unusual outbound network connections from several internal workstations to an external IP address known for hosting C2 (Command and Control) infrastructure. The connections are occurring over TCP port 443, but the traffic does not appear to be legitimate HTTPS. What technique is the attacker most likely employing?Security Monitoring
  33. 33.A security team is implementing a new Intrusion Prevention System (IPS) to protect the corporate network. The IPS is configured to block traffic based on known malicious patterns and signatures. Which detection method is this IPS primarily employing?Security Concepts
  34. 34.A security analyst is reviewing web server access logs. They notice a large number of HTTP GET requests to '/admin/login.php' from a single IP address, with each request containing a different, short string in the 'username' parameter (e.g., 'admin', 'test', 'root'). The HTTP response status codes are consistently 200 OK for most attempts, but a few return 401 Unauthorized. What type of attack is most likely occurring?Security Monitoring
  35. 35.A large multinational corporation is subject to the General Data Protection Regulation (GDPR) due to its operations in Europe. During an internal audit, it's discovered that customer data collected from European citizens is being stored on servers located in a country without an adequate level of data protection, and no appropriate safeguards (like Standard Contractual Clauses) are in place. Which GDPR principle is primarily being violated?Security Concepts
  36. 36.A security analyst is investigating a series of failed login attempts against a critical internal web application. The SIEM shows numerous authentication failures originating from an internal IP address that is not typically associated with administrative access. Further investigation reveals a pattern of attempts to guess common default credentials. Which type of attack is most likely occurring?Security Monitoring
  37. 37.A security team is conducting a penetration test on a new e-commerce platform. During the post-exploitation phase, the tester successfully establishes a persistent backdoor on a server and extracts sensitive customer data. What is the MOST critical next step the penetration tester should take before completing the engagement, according to ethical hacking principles?Vulnerability Management
  38. 38.A manufacturing company's operational technology (OT) network, which controls critical industrial processes, has recently been segmented from the corporate IT network. However, a security audit reveals that a single management workstation on the IT network still has direct RDP access to a critical controller on the OT network. This workstation is not subject to the same strict security controls as other OT-specific jump servers. Which security vulnerability does this scenario represent?Security Concepts
  39. 39.A security operations center (SOC) analyst observes a series of suspicious events originating from an internal server. The server, which should only be communicating internally, is attempting to establish outbound connections to various unusual IP addresses on TCP port 22. The analyst suspects unauthorized remote access attempts or data exfiltration. Which common network port is being observed and what is its primary legitimate use?Security Concepts
  40. 40.A security analyst is investigating an alert from an Intrusion Prevention System (IPS) that blocked suspicious network traffic. The alert indicates that the traffic contained a known exploit signature targeting a specific vulnerability in a web server application. The IPS successfully dropped the malicious packets and prevented the attack from reaching the server. Which type of network security control did the IPS primarily utilize in this scenario?Security Concepts
  41. 41.A security analyst is reviewing network traffic captured during an incident response. The analyst observes a large number of UDP packets originating from an internal host, destined for various external IP addresses, all on port 161. The payload of these packets appears to be standard SNMP GetRequest messages. What is the most likely malicious activity occurring?Security Monitoring
  42. 42.A security analyst is investigating a suspected malware infection on an internal host. The host is exhibiting unusual outbound connections to a known malicious IP address on TCP port 443, but the traffic does not appear to be encrypted with TLS/SSL as expected. Which type of intrusion is most likely occurring?Security Monitoring
  43. 43.A security architect is designing a system that requires ensuring data not only remains confidential but also that its origin can be reliably proven and that the sender cannot later deny having sent it. Which cryptographic principle is crucial for addressing the 'sender cannot deny' requirement?Security Concepts
  44. 44.A security analyst is reviewing a full packet capture (PCAP) file from a suspected data exfiltration incident. The analyst observes numerous small DNS query packets where the requested domain names appear to be unusually long and contain seemingly random alphanumeric strings, such as 'd29ybGRfZGF0YS50eHQ.attacker.com'. What technique is most likely being used for data exfiltration?Security Monitoring
  45. 45.A security analyst is reviewing NetFlow records for a critical server. They observe a significant increase in outbound traffic to a single external IP address over a short period, with packets consistently having a size of 64 bytes. The destination port is non-standard and varies frequently. What type of attack pattern does this most strongly suggest?Security Monitoring
  46. 46.A security analyst is investigating a persistent vulnerability identified during a recent scan of a legacy application server. The vulnerability is a known remote code execution (RCE) flaw in an outdated library that cannot be patched without breaking critical business functionality. The organization decides not to patch the vulnerability. Which of the following is the MOST appropriate risk mitigation strategy in this scenario?Vulnerability Management
  47. 47.An organization is deploying a new cloud-based application that will handle sensitive customer data. To ensure the application's security and prevent common vulnerabilities, the development team is advised to follow the 'secure by design' principle. Which action is the MOST crucial implementation of this principle?Security Concepts
  48. 48.A company is implementing a new BYOD (Bring Your Own Device) policy. To mitigate the risk of malware spreading from employees' personal devices to the corporate network, the security team decides to isolate personal devices and applications in a controlled environment. Which endpoint security concept is being applied here?Security Concepts
  49. 49.A security analyst receives an alert from the SIEM indicating 'Large file transfer to an unapproved cloud storage service' originating from a developer's workstation. The alert is triggered by a custom rule that monitors network traffic for connections to known cloud storage domains not on the corporate whitelist. Which type of security monitoring concept does this scenario primarily demonstrate?Security Monitoring
  50. 50.A security team is deploying a new web application and must ensure that all communication between clients and the server is encrypted and authenticated. Which cryptographic protocol is best suited for establishing a secure channel for this purpose over the internet?Security Concepts