Cisco CyberOps Associate (CBROPS) 200-201 practice questions

239 free questions with answers and explanations.

Practice test
  1. 51.A security auditor is reviewing an organization's cloud environment. The auditor identifies that several virtual machines (VMs) are configured with default administrative credentials and are directly exposed to the internet with unnecessary open ports. Which security vulnerability category does this scenario primarily represent?Security Concepts
  2. 52.A security analyst observes a flurry of network traffic alerts from the SIEM, all related to a single internal host. The alerts indicate attempts to connect to multiple external IP addresses on various high-numbered UDP ports, followed by a sudden decrease in the host's normal application traffic. What does this pattern of activity most strongly suggest?Security Monitoring
  3. 53.A global organization is mandated to comply with the European Union's General Data Protection Regulation (GDPR). The security team is reviewing its data handling practices to ensure compliance. Which GDPR principle specifically requires that personal data be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organizational measures?Security Concepts
  4. 54.A company is implementing a new BYOD (Bring Your Own Device) policy. To mitigate the risk of malware or data leakage from personal applications and data interfering with corporate resources on an employee's device, they decide to create isolated environments for corporate applications. What security concept is being utilized?Security Concepts
  5. 55.A security analyst is investigating an incident where a critical server experienced a sudden, massive influx of traffic from what appears to be a legitimate source, overwhelming its resources and making it unavailable. Further analysis reveals that the traffic consists of a large number of 'SYN' packets, but no corresponding 'ACK' packets are received from the server. What type of attack is this most indicative of?Security Concepts
  6. 56.A security analyst is investigating a series of alerts from the SIEM system indicating a high volume of failed login attempts against a critical internal database server. The attempts originate from various internal IP addresses, and each attempt uses a different username and password combination, cycling through a large dictionary of common credentials. What type of attack is most likely occurring?Security Concepts
  7. 57.A security analyst is investigating a compromised endpoint. During the forensic analysis, they discover that the malware found on the system changes its signature and characteristics each time it infects a new system or even within the same system over time. What type of malware is this?Security Concepts
  8. 58.A SIEM administrator is configuring a new data source for a critical web application. To ensure effective security monitoring, which of the following log types should be prioritized for ingestion to provide insights into user authentication, authorization, and potential web-based attacks?Security Monitoring
  9. 59.A security analyst is investigating a series of alerts from a host-based intrusion detection system (HIDS) indicating unusual activity on a critical server. The alerts show multiple failed login attempts from a single source IP address targeting various user accounts within a short period. Which type of attack is most likely being attempted?Security Monitoring
  10. 60.A security analyst is investigating a series of alerts from a SIEM indicating 'High Volume of Outbound SMB Traffic' from an internal file server to numerous internal workstations, occurring outside business hours. Further investigation reveals that the file server is not typically used to initiate SMB connections to workstations, but rather to serve files. What is the most likely cause of this activity?Security Monitoring
  11. 61.A security auditor is reviewing an organization's access control policies. The auditor notes that standard users are granted read-only access to configuration files, while administrators have full read/write/execute permissions. However, a specific system configuration file, critical for network operations, is only accessible by a dedicated 'network_ops' service account, even for administrators. Which security principle is best exemplified by the access policy for the 'network_ops' service account?Security Concepts
  12. 62.A security analyst is reviewing NetFlow records for a critical database server and notices a high volume of outbound UDP traffic on port 53 to external, non-authoritative DNS servers. The traffic pattern shows small, frequent queries and large, fragmented responses. What type of data exfiltration technique is most likely occurring?Security Monitoring
  13. 63.A security team is implementing a new endpoint detection and response (EDR) solution. As part of the rollout, they configure the EDR agents to monitor all process executions, file system changes, and network connections on workstations. Which security monitoring concept is primarily being enhanced by this implementation?Security Concepts
  14. 64.An organization is implementing a continuous vulnerability management program. As part of this, they need to ensure that security vulnerabilities are classified consistently and that information about them can be easily shared and understood across different security tools and teams. Which standardized system is primarily used for this purpose, providing unique identifiers and common names for publicly known information security vulnerabilities?Vulnerability Management
  15. 65.A security auditor is reviewing an organization's patch management policy. The policy states that 'critical security patches must be applied to production systems within 72 hours of release, provided they pass staging environment testing.' However, the auditor discovers that due to resource constraints and complex interdependencies, many critical patches are routinely delayed for weeks. What is the auditor's most significant concern regarding this discrepancy?Vulnerability Management
  16. 66.A security analyst is reviewing a vulnerability scan report for a critical database server. The report indicates a 'High' severity vulnerability related to an unpatched operating system. The analyst confirms the OS version is indeed outdated. However, the report also lists a 'Medium' severity vulnerability for an open port 3389 (RDP) but states that the service is configured to only allow connections from an internal jump host and requires multi-factor authentication (MFA). Which of the following is the MOST appropriate next step for the RDP vulnerability?Vulnerability Management
  17. 67.A large e-commerce company is preparing to launch a new version of its online store. Before release, the security team conducts a comprehensive audit to identify and remediate potential weaknesses. During this audit, they discover that the application uses a default administrative password that was not changed during installation. Which common security vulnerability does this represent?Security Concepts
  18. 68.A security analyst is reviewing network traffic and observes a high volume of fragmented IP packets, many of which overlap or have invalid offsets. The destination IP address is a critical web server. This activity is causing the server to become unresponsive. Which type of attack is most likely occurring?Security Monitoring
  19. 69.A company is implementing a new security awareness program. A key component of the program is to educate employees on recognizing and reporting phishing attempts. Which security principle is primarily addressed by this initiative?Security Concepts
  20. 70.A company is implementing a new security policy that requires all remote access to internal resources to be encrypted and authenticated using multi-factor authentication. Which security principle is primarily being addressed by these requirements?Security Concepts
  21. 71.A security analyst is investigating a host that is unresponsive and exhibiting extremely high CPU utilization. Process monitoring shows a single process consuming nearly 100% of the CPU, and its memory footprint is unusually large and constantly growing. The process name is generic (e.g., 'svchost.exe' on Windows, but not a legitimate system process). What type of host-based intrusion is most likely occurring?Security Monitoring
  22. 72.A security auditor is reviewing an organization's access control policies. The auditor notes that several employees have retained access to systems and data even after transferring to different departments where their previous access is no longer required for their job functions. Which security principle is being violated?Security Concepts
  23. 73.A security operations center (SOC) analyst receives an alert from the SIEM indicating 'Multiple failed login attempts' for a critical administrative account on a domain controller. This alert is immediately followed by 'Successful login' from an unknown external IP address. What is the most appropriate immediate action for the analyst to take?Security Monitoring
  24. 74.A security analyst is investigating a series of alerts indicating that multiple internal hosts are attempting to connect to an external IP address on port 443, but the traffic does not appear to be legitimate HTTPS. Further analysis reveals that the communication pattern is unusual and inconsistent with normal web browsing. Which common attack vector is most likely being utilized in this scenario?Security Concepts
  25. 75.A security operations center (SOC) analyst observes a significant increase in outbound UDP traffic originating from internal network devices, specifically targeting various external DNS servers. The traffic volume is exceptionally high, and the source IP addresses of the internal devices appear to be legitimate, but the nature of the DNS queries is unusual. Which type of attack is most likely occurring?Security Concepts
  26. 76.A security auditor is reviewing the incident response plan for a critical infrastructure organization. The plan outlines specific steps for isolating compromised systems, eradicating malware, and restoring affected services from backups. Which phase of the incident response lifecycle do these actions primarily fall under?Security Concepts
  27. 77.A security analyst is investigating a critical alert from the SIEM indicating 'Suspicious process execution from an unusual directory' on a Windows server. Further examination shows that a process named 'iexplore.exe' (Internet Explorer) was launched from the 'C:\Temp\' directory, and it is making outbound connections to a known malicious IP address. What type of host-based intrusion is this most likely an indicator of?Security Monitoring
  28. 78.A security team is implementing a new access control system. The policy dictates that users should only be granted the minimum necessary permissions to perform their job functions and no more. For example, a data entry clerk should only have read/write access to specific database tables and no administrative privileges. Which security principle is being applied?Security Concepts
  29. 79.A security auditor is reviewing a web application and discovers that it is vulnerable to cross-site request forgery (CSRF) attacks. This vulnerability means that a malicious website could trick a user's browser into sending an authenticated request to the vulnerable application. Which security principle is most directly violated by this vulnerability?Security Concepts
  30. 80.A security team is implementing a new endpoint detection and response (EDR) solution. The EDR is configured to collect data on normal user behavior, process execution, and network connections. It then uses this baseline to identify unusual activities that deviate significantly from the established norms. What type of detection method is the EDR primarily employing?Security Concepts
  31. 81.An organization is deploying a new web application that will handle sensitive customer data. The security team wants to ensure that all communication between the client's browser and the web server is encrypted and that the server's identity is authenticated. Which protocol should be implemented to achieve these security goals?Security Concepts
  32. 82.A company policy dictates that all critical servers must be patched within 72 hours of a security patch release. A recent vulnerability scan report shows that several critical servers have not received a widely publicized patch for a severe OS vulnerability, 96 hours after its release. This situation indicates a failure in which aspect of vulnerability management?Vulnerability Management
  33. 83.A security analyst is investigating a series of anomalies on a corporate network. They observe that several internal hosts are making repeated outbound connections to a known malicious IP address on port 53, and the data exchanged appears to be disguised as DNS queries and responses. What type of attack is most likely occurring?Security Concepts
  34. 84.A security team is analyzing network traffic logs and observes a significant increase in connection attempts to various internal systems from an external IP address. The attempts are using a common set of usernames and passwords that appear to be dictionary words and simple combinations. What type of attack is most likely occurring?Security Concepts
  35. 85.A security analyst is reviewing logs after a recent vulnerability scan of several web servers. The scan report indicates multiple instances of 'CVE-2023-XXXX' related to outdated Apache HTTP Server versions. The analyst needs to determine the immediate next step to mitigate this specific vulnerability. Which action should the analyst prioritize?Vulnerability Management
  36. 86.A financial institution is upgrading its data protection measures to comply with stringent new privacy regulations. The regulations require that sensitive customer data, even when processed in the cloud by a third-party vendor, must remain encrypted throughout its entire lifecycle, including during computation. Which advanced cryptographic technique can achieve this 'encryption in use' capability?Security Concepts
  37. 87.A security analyst discovers several new, unauthorized user accounts with administrative privileges created on a critical database server. Audit logs show these accounts were created shortly after a successful 'SQL query containing xp_cmdshell' from an external IP address. What phase of the cyber kill chain does the creation of these new accounts represent?Security Monitoring
  38. 88.A security operations center (SOC) analyst observes a series of suspicious events originating from an external IP address attempting to establish connections to internal servers on port 22. Multiple failed login attempts are logged, and the traffic appears to be encrypted. Which protocol is being targeted, and what is the common attack vector indicated by these observations?Security Concepts
  39. 89.A security analyst is reviewing a firewall's configuration rules. One rule permits all outbound traffic from the internal network to the internet, while another rule explicitly denies traffic to known malicious IP addresses. However, if a rule for a specific type of traffic (e.g., a particular port) is not explicitly defined, the firewall automatically blocks it. Which firewall rule philosophy is being applied here?Security Concepts
  40. 90.A new regulation mandates that all sensitive data processing systems undergo a comprehensive security assessment annually. The assessment must include a method to simulate real-world attacks to identify exploitable vulnerabilities, not just potential ones. Which type of assessment would BEST fulfill this regulatory requirement?Vulnerability Management
  41. 91.A software development team is adopting a 'secure by design' approach for their new application. During the architecture phase, they are focusing on identifying potential attack surfaces and designing controls to mitigate risks before any code is written. Which activity is a critical part of implementing 'secure by design' at this early stage?Security Concepts
  42. 92.A large enterprise is evaluating multiple vulnerability scanning tools. One tool offers both agent-based and agentless scanning capabilities. The enterprise has a highly dynamic cloud environment with frequently changing virtual machines and containers, and also a stable on-premises infrastructure. Which statement accurately describes the optimal use of these scanning capabilities for this enterprise?Vulnerability Management
  43. 93.A security analyst is reviewing network traffic logs and observes a high volume of ICMP echo requests targeting various internal hosts from an external IP address. The analyst also notes that the external IP address appears to be spoofed. Which type of attack is most likely occurring?Security Concepts
  44. 94.A security operations center (SOC) analyst observes a significant increase in outbound UDP traffic on port 123 (NTP) from several internal servers to external NTP servers, far exceeding normal baseline levels. The source IP addresses are legitimate internal servers, but the destination IP addresses are varied and appear to be victims. What type of attack is most likely underway?Security Concepts
  45. 95.A security team is preparing to conduct a vulnerability scan on a production environment. To minimize potential disruption to critical services, they decide to use a non-intrusive scanning approach. Which of the following best describes the characteristics of such a scan?Vulnerability Management
  46. 96.A global organization is mandated to comply with the General Data Protection Regulation (GDPR) for all personal data belonging to EU citizens. The regulation emphasizes that personal data must be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures. Which core GDPR principle is this statement directly addressing?Security Concepts
  47. 97.A security analyst is reviewing a firewall's configuration rules. One rule permits all outbound traffic from the internal network to external destinations on TCP port 53. Another rule permits inbound traffic on TCP port 80 to a web server. Which core network security concept is being demonstrated by explicitly defining allowed traffic and implicitly denying all other traffic?Security Concepts
  48. 98.A security analyst is reviewing NetFlow records for a critical database server and notices a sudden, sustained increase in outbound traffic to an unfamiliar external IP address on port 53 (DNS). The traffic volume is significantly higher than typical DNS traffic for this server. What type of activity does this pattern most likely indicate?Security Monitoring
  49. 99.An organization uses a Security Information and Event Management (SIEM) system to aggregate and analyze security logs. Recently, a new application was deployed that generates a high volume of legitimate, but verbose, log entries. This has led to a significant increase in SIEM storage consumption and processing load, causing some critical alerts to be delayed. What SIEM optimization technique should be applied first to address this issue?Security Monitoring
  50. 100.A penetration tester is conducting a black-box test against a web application. During the reconnaissance phase, they discover that the application is running an older version of a popular content management system (CMS) for which several public exploits are available. Which of the following actions is the MOST appropriate next step for the penetration tester, adhering to ethical hacking principles?Vulnerability Management