Cisco CyberOps Associate (CBROPS) 200-201 practice questions

239 free questions with answers and explanations.

Practice test
  1. 101.A security team is implementing a new endpoint detection and response (EDR) solution. As part of its advanced threat detection capabilities, the EDR system is configured to continuously monitor user and system activities on endpoints, looking for deviations from established baselines or known normal patterns. For example, it might flag an unusual executable launching from a temporary directory and attempting to connect to a suspicious external IP address. Which security monitoring concept is primarily being utilized by this EDR feature?Security Concepts
  2. 102.A forensic investigator is analyzing a compromised endpoint. The investigation reveals that malware was able to evade detection by modifying its signature multiple times, making it difficult for traditional antivirus software to identify. Which type of malware characteristic allowed it to bypass signature-based detection?Security Concepts
  3. 103.A security auditor is reviewing an organization's cloud environment. The auditor identifies several storage buckets that are publicly accessible without authentication, exposing sensitive customer data. Which common security vulnerability does this situation represent?Security Concepts
  4. 104.A security analyst is reviewing a vulnerability scan report that lists several findings. One particular finding is rated 'High' severity and details a missing security update for an operating system component that allows remote code execution. However, the analyst knows the component is not installed or used on the affected servers. What is the most appropriate classification for this finding in the context of the organization's risk?Vulnerability Management
  5. 105.A security analyst is reviewing a SIEM dashboard and notices a sudden, significant increase in firewall 'deny' events for outbound traffic to a wide range of external IP addresses, all destined for TCP port 80 and 443. This activity originates from a single internal subnet that typically has minimal outbound web traffic. What is the most likely cause of this alert pattern?Security Monitoring
  6. 106.A security analyst is investigating a suspected malware infection on a Windows endpoint. During host-based analysis, the analyst discovers a new process running with administrator privileges that is not digitally signed and is located in a highly unusual directory, 'C:\ProgramData\Temp\svchost.exe'. What is the most immediate concern raised by this discovery?Security Monitoring
  7. 107.A security analyst is investigating a host that is exhibiting suspicious behavior, including unexpected outbound connections and high CPU usage. The analyst gathers a memory dump from the compromised system. Which type of analysis is being performed?Security Monitoring
  8. 108.A security consultant is asked to perform a vulnerability assessment for a client's internal network. The client explicitly states that the assessment must be conducted from the perspective of an authenticated user with standard domain user privileges to identify vulnerabilities accessible to a typical employee. Which type of vulnerability scanning approach should the consultant primarily utilize?Vulnerability Management
  9. 109.A global company is expanding its operations into new regions and must comply with various international data privacy regulations, including GDPR and CCPA. The legal team is concerned about data residency requirements, where certain types of data must physically remain within specific geographic borders. Which security program element is primarily responsible for ensuring the company adheres to these complex legal and regulatory mandates?Security Concepts
  10. 110.A security analyst is investigating a series of alerts indicating unusual outbound traffic from a web server. The alerts show connections being established to various external IP addresses on TCP port 53. The web server should only be communicating with internal DNS resolvers. Which common attack vector is most likely being exploited?Security Concepts
  11. 111.A company is implementing a bring-your-own-device (BYOD) policy. To mitigate the risk of malware spreading from personal devices to the corporate network, the security team decides to isolate corporate applications and data within a secure, encrypted container on each employee's device. What endpoint security concept does this strategy represent?Security Concepts
  12. 112.A security analyst is reviewing a custom application's log files after a report of anomalous behavior. The logs show numerous entries similar to: 'User: admin, Action: login, Status: Failed, SourceIP: 192.168.1.100, Timestamp: 2023-10-27 14:35:01'. The analyst needs to quickly filter these logs to show only successful administrative actions. Which log analysis technique would be most efficient for this task?Security Monitoring
  13. 113.A security analyst is investigating a series of alerts from a web application firewall (WAF) indicating 'Excessive Login Failures' originating from a single external IP address. The pattern shows thousands of unique username attempts against the login page within a short period. Which attack technique is most accurately described by this activity?Security Monitoring
  14. 114.A software development team is adopting a 'secure by design' approach for their new application. Which of the following best describes a key characteristic of this approach?Security Concepts
  15. 115.A security analyst is reviewing network traffic logs and observes a high volume of TCP SYN packets originating from a single external IP address directed towards multiple internal hosts on various ports. There are very few corresponding SYN-ACK or ACK packets. What type of attack is most likely occurring?Security Monitoring
  16. 116.An organization is deploying a new web application that will handle sensitive customer payment information. To comply with PCI DSS requirements and ensure the integrity and confidentiality of data in transit, which cryptographic protocol should be implemented?Security Concepts
  17. 117.A security analyst is investigating a series of alerts from an Endpoint Detection and Response (EDR) solution indicating a suspicious process attempting to inject code into another legitimate process on a Windows host. The legitimate process is 'explorer.exe'. What is this type of activity commonly referred to in host-based intrusion analysis?Security Monitoring
  18. 118.A security team is implementing a new endpoint detection and response (EDR) solution. The solution is configured to continuously monitor system calls, process activity, and file system changes on endpoints. It then uses machine learning to identify deviations from normal behavior patterns to detect potential threats, even if they are previously unknown. What security monitoring concept is primarily being utilized by this EDR solution?Security Concepts
  19. 119.A security analyst is investigating a critical alert from a SIEM indicating 'Unauthorized Access Attempt' on a web server. The alert details show a series of HTTP POST requests to a login endpoint, with the 'User-Agent' header consistently set to 'Mozilla/5.0 (compatible; Nmap Scripting Engine)'. What is the primary implication of this User-Agent string?Security Monitoring
  20. 120.A small business has recently installed a new web application and wants to ensure it is secure against common web vulnerabilities. They have limited budget and technical staff. Which type of vulnerability assessment would be most appropriate for their initial security review?Vulnerability Management
  21. 121.A security analyst is conducting a vulnerability assessment of a critical web server. During the initial information gathering phase, they discover that the server is running an outdated version of Apache HTTP Server. Which of the following is the MOST immediate and effective action the analyst should recommend to address this specific finding?Vulnerability Management
  22. 122.A security operations center (SOC) analyst is investigating a series of failed login attempts from an external IP address targeting a public-facing web server. The analyst observes that the attacker is attempting to use a small list of commonly known usernames (e.g., 'admin', 'test', 'user') combined with a large dictionary of passwords. What type of attack is this most indicative of?Security Concepts
  23. 123.A global organization is mandated to comply with the European Union's General Data Protection Regulation (GDPR). As part of their compliance efforts, they are implementing measures to ensure that personal data is processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures. Which GDPR principle is primarily being addressed here?Security Concepts
  24. 124.A security analyst observes numerous attempts to access a specific URL parameter with various SQL commands (e.g., 'UNION SELECT', 'OR 1=1--'). These attempts are coming from a single IP address over a short period. Which host-based intrusion analysis technique would be most effective in confirming if the web application is vulnerable to this attack?Security Monitoring
  25. 125.A security analyst is reviewing network traffic logs and observes a significant volume of UDP traffic originating from internal hosts to external DNS servers, with unusually large response packets. This traffic pattern is inconsistent with normal DNS queries and responses. What type of attack is most likely indicated?Security Concepts
  26. 126.A security auditor is reviewing a web application and discovers that it is vulnerable to cross-site scripting (XSS) attacks. An attacker could inject malicious scripts into web pages viewed by other users. If successful, this could allow the attacker to steal session cookies, deface websites, or redirect users to malicious sites. Which component of the CIA triad is primarily compromised by a successful XSS attack that allows an attacker to steal user session cookies?Security Concepts
  27. 127.A security team is deploying a new web application that will handle sensitive customer payment information. To protect data in transit, they decide to implement strong encryption and ensure that all communication between the client's browser and the web server is secure. Which cryptographic protocol is most suitable for this purpose?Security Concepts
  28. 128.A security team is performing a vulnerability assessment on a critical internal server. They have administrator credentials for the server and intend to use them during the scan to get a comprehensive view of potential vulnerabilities, including misconfigurations and missing patches. What type of scan is being performed?Vulnerability Management
  29. 129.A security analyst is investigating a series of failed login attempts to a critical server. The attempts originate from various IP addresses globally, but all target the administrator account. Which common attack vector does this scenario most likely represent?Security Concepts
  30. 130.During a network intrusion analysis, a security analyst identifies a series of port scans originating from an external IP address. The scans involve sequentially attempting connections to every port from 1 to 1024 on a target host. Which type of port scan is being conducted?Security Monitoring
  31. 131.A security analyst is investigating a suspected insider threat. The SIEM shows a user account, 'jdoe', accessing a large number of sensitive financial documents from a network share at 3 AM, outside of normal business hours. 'jdoe' is an authorized user of these documents during the day. What type of security event data analysis would be most effective in detecting this specific anomaly?Security Monitoring
  32. 132.A financial institution is performing a penetration test on its core banking application. The scope of work explicitly states that the penetration tester is NOT allowed to cause any service disruption or data corruption. During the test, the tester identifies a critical SQL injection vulnerability that could lead to full database compromise. What is the MOST appropriate action for the penetration tester to take?Vulnerability Management
  33. 133.A security analyst is reviewing a SIEM alert for a critical web application. The alert, generated by a correlation rule, indicates 'Multiple Failed Login Attempts from Geographically Disparate Locations within 5 Minutes'. The baseline for this application shows users typically log in from a single, consistent location. What type of attack is this correlation rule designed to detect?Security Monitoring
  34. 134.An organization is migrating its on-premises applications to a public cloud environment. The security team is involved from the very beginning of the migration project, ensuring that security requirements are integrated into the architecture design, development, and deployment phases. This approach aims to prevent vulnerabilities rather than fixing them after they occur. Which security concept is being demonstrated?Security Concepts
  35. 135.A security analyst is reviewing a SIEM dashboard and observes a series of alerts indicating 'Unauthorized modification of system binaries' on multiple Linux servers. Further investigation reveals that the 'ls' and 'ps' commands are reporting inaccurate information, and some running processes are not visible through standard tools. What type of malicious software is most likely at play?Security Monitoring
  36. 136.A financial institution is upgrading its data protection measures to comply with stringent new privacy regulations. They want to perform analytics on encrypted customer data without decrypting it, to avoid exposing sensitive information during processing. Which advanced cryptographic technique enables computation on ciphertext, yielding an encrypted result that, when decrypted, matches the result of operations performed on the plaintext?Security Concepts
  37. 137.A financial institution is upgrading its data protection measures to comply with stringent regulatory requirements. They need a cryptographic solution that can encrypt data at rest, but also allow for efficient searching and processing of encrypted data without decrypting the entire dataset. Which advanced cryptographic concept is best suited for this specific requirement?Security Concepts
  38. 138.A security incident response team is alerted to unusual outbound network traffic from several internal workstations to an unknown external IP address. Further investigation reveals that a new, unauthorized process is running on these machines, attempting to establish command-and-control communication. The team needs to quickly identify the type of malware responsible and its communication method. Which security monitoring concept is critical for detecting and analyzing this type of activity?Security Concepts
  39. 139.A security team is evaluating a new data loss prevention (DLP) solution. They want to ensure that the DLP system's rules align perfectly with the organization's data classification policy, which defines what constitutes 'sensitive data' and how it should be handled. This alignment is critical for preventing both false positives and false negatives. Which aspect of security policy implementation is the team primarily focusing on during this evaluation?Security Policies and Procedures
  40. 140.A financial institution is implementing a new data retention policy to comply with GDPR regulations. The policy specifies that customer transaction data must be anonymized or deleted after seven years. Which core principle of data privacy is this policy primarily addressing?Security Policies and Procedures
  41. 141.A security analyst is using Wireshark to analyze a PCAP file. They need to quickly identify all packets associated with a specific TCP session to understand the full flow of communication. Which Wireshark feature would be most efficient for this task?Network Intrusion Analysis
  42. 142.An organization relies heavily on cloud services for its operations. A recent security assessment revealed that several cloud-based applications are not regularly backed up, and there is no clear process for restoring data in the event of a service outage or cyberattack. Which aspect of security policies and procedures is most directly impacted by this finding?Security Policies and Procedures
  43. 143.A network security analyst is deploying a new intrusion prevention system (IPS) in an inline configuration. Which of the following is a primary concern for the analyst regarding the IPS's impact on network traffic flow?Network Intrusion Analysis
  44. 144.A new employee is onboarding at a tech company. During their initial security training, they are taught about phishing awareness, safe browsing habits, and the company's policy on reporting suspicious emails. Which of the following is the primary goal of this type of training?Security Policies and Procedures
  45. 145.A security analyst is investigating a suspected malware infection on a host. Network forensic analysis shows a persistent connection to an external IP address, with small, periodic data transfers. The external IP address resolves to a domain with a suspicious, randomly generated subdomain. No legitimate application on the host is known to communicate with this domain. What does this pattern of communication most strongly suggest?Network Intrusion Analysis
  46. 146.A security operations center (SOC) receives an alert indicating unusual outbound network traffic from an internal server to an unknown external IP address. The SOC team immediately initiates their defined incident response procedure, which includes verifying the alert, isolating the server, and collecting forensic images. This systematic approach, driven by a pre-defined set of actions for specific types of security events, best exemplifies the organization's commitment to which security concept?Security Policies and Procedures
  47. 147.A security analyst is performing a forensic investigation on a server that was recently compromised. They discover a malicious script that attempts to allocate an excessively large amount of memory, exceeding the buffer size intended for a specific program. This action subsequently overwrites adjacent memory locations, including the return address, to execute arbitrary code. What type of vulnerability is being exploited?Network Intrusion Analysis
  48. 148.A security analyst is investigating a suspected insider threat. They need to capture all network traffic from a specific workstation to an external cloud storage service, but the workstation is connected to a Gigabit Ethernet switch that does not support port mirroring. Which network device would be most effective for passively capturing this traffic without disrupting the workstation's network connectivity?Network Intrusion Analysis
  49. 149.A security analyst is investigating a network segment and notices a significant increase in ARP requests and responses, with multiple MAC addresses being associated with the same IP address over a short period. This activity is occurring on a local subnet and is causing intermittent connectivity issues for legitimate hosts. What type of network attack is most likely taking place?Network Intrusion Analysis
  50. 150.A security analyst is investigating a potential compromise involving a web server. The analyst discovers a large number of HTTP GET requests to a non-existent file path, `/.env`, from various external IP addresses. These requests are occurring rapidly and originate from different geographical locations. What type of attack is most likely underway?Network Intrusion Analysis