Cisco CyberOps Associate (CBROPS) 200-201 practice questions

239 free questions with answers and explanations.

Practice test
  1. 151.A security analyst is investigating a series of alerts from an Intrusion Prevention System (IPS) indicating attempts to exploit a web server. The alerts show that an attacker is sending requests with unusually large HTTP POST bodies, often containing seemingly random data. These requests are causing the web server process to crash or become unresponsive. What type of attack is most likely being attempted?Network Intrusion Analysis
  2. 152.A company recently underwent a major organizational restructuring, resulting in many employees changing departments or roles. The existing security policies include guidelines for data access based on job function, but the process for reviewing and updating these access rights has not been consistently followed during the transition. This oversight directly increases the risk of violating which security principle?Security Policies and Procedures
  3. 153.A company is developing a security awareness program for its employees. They want to ensure that the training effectively changes employee behavior regarding phishing emails. Which metric would be MOST effective in assessing the success of this objective?Security Policies and Procedures
  4. 154.An organization's security policy states that all critical servers must be patched within 48 hours of a patch release for high-severity vulnerabilities. However, the system administrators have developed a detailed, step-by-step document outlining the specific process for patch deployment, including testing procedures, rollback plans, and communication protocols. This detailed document serves what primary purpose within the organization's security framework?Security Policies and Procedures
  5. 155.A security analyst is examining a PCAP file and notices a series of TCP connections where the SYN and ACK flags are set in the initial handshake, but the PSH flag is immediately set in subsequent data packets, even for very small payloads. This occurs repeatedly from an internal host to several external IP addresses known to be associated with command-and-control infrastructure. What network intrusion technique does this behavior most strongly suggest?Network Intrusion Analysis
  6. 156.An organization is auditing its security procedures. It discovers that while there is a written policy requiring multi-factor authentication (MFA) for all remote access, many employees are circumventing it by using older, unpatched VPN clients that do not enforce MFA. What type of security control failure does this scenario represent?Security Policies and Procedures
  7. 157.A security analyst is monitoring network traffic and observes a series of outbound TCP SYN packets from an internal host to a target external server, followed by RST packets from the target. No SYN-ACK packets are received by the internal host. This pattern repeats across a range of destination ports. What type of activity is most likely occurring?Network Intrusion Analysis
  8. 158.A network security analyst is investigating an alert from an Intrusion Detection System (IDS) indicating a potential port scan. The alert shows multiple connection attempts to various ports on a single host from a single source IP address within a short time frame. Which Nmap command would an attacker typically use to perform such a scan without triggering common firewall rules designed to block full TCP connections?Network Intrusion Analysis
  9. 159.A network security analyst is reviewing a packet capture (PCAP) file from a compromised host. They observe a large number of outbound HTTP GET requests to various subdomains of an unfamiliar domain, such as 'a.malicious.com', 'b.malicious.com', 'c.malicious.com', and so on. The subdomains appear to be randomly generated. What network intrusion technique does this pattern suggest?Network Intrusion Analysis
  10. 160.A security team is analyzing a suspicious executable found on an internal host. Initial dynamic analysis in a sandbox reveals that the executable attempts to connect to a hardcoded external IP address on TCP port 4444 and then sends an encrypted blob of data. The host's firewall logs confirm a successful outbound connection to this IP and port. What type of malware communication is most likely indicated by this behavior?Network Intrusion Analysis
  11. 161.A security analyst is examining a network capture for signs of malware. They observe multiple outbound HTTP requests from an internal host to various, seemingly random, subdomains under a single legitimate-looking top-level domain (e.g., `randomstring1.legitdomain.com`, `randomstring2.legitdomain.com`). The response sizes are consistently small. What technique is this malware most likely employing for its command and control (C2) communication?Network Intrusion Analysis
  12. 162.A security analyst is reviewing NetFlow records and notices a persistent, low-volume communication pattern between an internal host and an external IP address. The communication consists of small, encrypted packets occurring at regular, fixed intervals (e.g., every 60 seconds). This pattern is inconsistent with normal user activity or known applications. What does this communication pattern most likely indicate?Network Intrusion Analysis
  13. 163.A security engineer is tasked with creating a new procedure for handling sensitive customer data. The organization's overarching data protection policy mandates that 'all personally identifiable information (PII) must be encrypted both in transit and at rest.' Which of the following best describes the role of the security engineer in translating this policy into an effective procedure?Security Policies and Procedures
  14. 164.A cybersecurity analyst is reviewing an organization's incident response plan. They notice that the plan clearly defines roles and responsibilities for each team member, outlines communication protocols, and specifies technical procedures for containment and eradication. However, the plan lacks a formal process for identifying and documenting lessons learned after an incident. Which phase of the incident response lifecycle is most directly impacted by this omission?Security Policies and Procedures
  15. 165.During a routine security audit, it is discovered that several employees are sharing login credentials for a critical production server, despite a clear organizational policy prohibiting this practice. The audit report identifies this as a significant vulnerability. Which type of security assessment would be most appropriate to systematically identify the extent of such policy violations and the potential impact across the organization?Security Policies and Procedures
  16. 166.A security operations center (SOC) analyst observes unusual outbound network connections from an internal server to an external IP address on TCP port 53. The internal server is not configured to perform DNS resolution for external clients, and the traffic volume is significantly higher than normal DNS queries. What is the most likely initial conclusion regarding this activity?Network Intrusion Analysis
  17. 167.A network security analyst is tasked with deploying a new network intrusion detection system (NIDS) in a critical segment of the corporate network. The NIDS needs to monitor all traffic passively without introducing latency or altering network packets. Which deployment mode is most appropriate for this requirement?Network Intrusion Analysis
  18. 168.A security analyst is investigating a web server that exhibited unusual outbound connections. They are examining HTTP traffic in a packet capture (PCAP) and observe multiple GET requests to an external domain, where the requested URL path contains long, seemingly random strings of alphanumeric characters. The 'User-Agent' string also appears unusual and inconsistent with typical browsers. Which type of attack or malware activity does this pattern most strongly suggest?Network Intrusion Analysis
  19. 169.A security analyst discovers that an attacker has gained unauthorized access to a critical database server by exploiting a known vulnerability. The organization's incident response plan outlines immediate steps to isolate the compromised server from the network. This action is primarily aimed at preventing the attacker from moving laterally to other systems or exfiltrating more data. Which incident response phase does this isolation strategy represent?Security Policies and Procedures
  20. 170.A security auditor is performing a post-incident review following a successful phishing attack that led to data exfiltration. The review identifies that while the organization had an up-to-date incident response plan, employees were unaware of the specific steps to report a suspicious email or whom to contact outside of business hours. This scenario indicates a weakness in which area of the security program?Security Policies and Procedures
  21. 171.A security operations center (SOC) analyst is investigating an alert indicating a potential port scan originating from an external IP address against several internal servers. Reviewing the firewall logs, the analyst observes numerous connection attempts to various ports (e.g., 22, 23, 80, 443, 3389) on different internal hosts within a short time frame, with most connections being reset (RST flag) by the internal servers. What type of scanning activity is most likely occurring?Network Intrusion Analysis
  22. 172.A security analyst is investigating a web server that has been defaced. During the forensic analysis of web server logs, they find entries indicating unusual requests containing snippets of SQL code, such as 'UNION SELECT' or 'OR 1=1--'. These requests appear to be attempting to manipulate the underlying database queries. What type of attack is indicated by these log entries?Network Intrusion Analysis
  23. 173.A new employee, unfamiliar with the organization's data handling guidelines, inadvertently uploads sensitive customer data to a publicly accessible cloud storage service. This incident highlights a gap in the organization's security posture. Which type of security control, if adequately implemented, would have been most effective in preventing this particular incident?Security Policies and Procedures
  24. 174.An organization is preparing for an upcoming regulatory audit. To ensure readiness, the security team conducts internal assessments, reviews all security documentation, and performs mock audits. Despite these efforts, a critical finding from a previous audit—the lack of documented procedures for secure disposal of retired hard drives—has not been fully addressed. This oversight represents a failure in what key aspect of security audits?Security Policies and Procedures
  25. 175.A network administrator observes a significant increase in network latency and packet loss across a specific network segment. Upon investigation, they find that a single host on that segment is sending a continuous stream of malformed or excessively large packets, overwhelming the local switch and other devices. This is causing legitimate traffic to be dropped. What type of attack is occurring?Network Intrusion Analysis
  26. 176.A large multinational corporation is developing a new security policy for its cloud infrastructure. The policy mandates that all data stored in the cloud must be encrypted both in transit and at rest, regardless of its classification. This policy aims to protect data even if the cloud provider's physical security is compromised. Which security goal is this policy primarily trying to achieve?Security Policies and Procedures
  27. 177.During a routine audit, it is discovered that an organization's security policy on remote access states that 'all remote connections must be secured.' However, there is no documented procedure detailing how to establish a VPN connection, which VPN client to use, or how to troubleshoot common connection issues. This scenario highlights a gap between which two crucial elements of a security program?Security Policies and Procedures
  28. 178.A security analyst is reviewing a packet capture and observes numerous outbound UDP packets on port 53 (DNS) to an external DNS server, where the query names are unusually long, randomly generated strings, and the responses are similarly large. This behavior is originating from a compromised internal host. What type of covert channel or exfiltration technique does this most likely represent?Network Intrusion Analysis
  29. 179.A security analyst is examining a PCAP file and notices a sequence of TCP packets with the PSH and ACK flags set, immediately followed by FIN and ACK flags, all within a very short timeframe from a client to a server. The data payload in the PSH/ACK packet is small. What does this specific flag sequence and timing most likely indicate about the communication?Network Intrusion Analysis
  30. 180.A security analyst is investigating an alert from a web application firewall (WAF) indicating a potential attack. The WAF logs show multiple requests to a web application where the 'User-Agent' header contains a string like '() { :;}; /bin/bash -c "echo pwned"'. This pattern is associated with attempts to execute arbitrary commands on the server. What type of vulnerability is being exploited?Network Intrusion Analysis
  31. 181.A security auditor is reviewing an organization's change management process. The auditor discovers that critical security patches are often deployed to production systems without prior testing in a staging environment, leading to system outages. This practice violates the organization's own policy for change management. Which aspect of security governance is primarily failing?Security Policies and Procedures
  32. 182.An organization is developing a new security policy. The policy states that all employees must use strong, unique passwords for all company systems and that multi-factor authentication (MFA) is mandatory for remote access. This policy is then communicated to all employees through email and a mandatory training session. Which characteristic of a well-defined security policy is best exemplified by the mandatory training session?Security Policies and Procedures
  33. 183.A security analyst is investigating a series of failed login attempts on a critical server. The log entries show repeated connection attempts from various external IP addresses to the server's SSH port (22) within a short period, each with different usernames and passwords. The attempts are quickly rejected by the server. What type of attack does this activity represent?Network Intrusion Analysis
  34. 184.A financial institution is implementing security awareness training for its employees. The training program includes modules on phishing recognition, strong password practices, and data privacy regulations (e.g., GDPR, CCPA) relevant to their operations. Which attribute of effective security awareness training is best demonstrated by the inclusion of content specific to data privacy regulations?Security Policies and Procedures
  35. 185.A healthcare organization is preparing for an audit of its HIPAA compliance. The audit specifically focuses on ensuring that electronic protected health information (ePHI) is only accessible by authorized personnel who require it for their job functions. Which security principle is being evaluated?Security Policies and Procedures
  36. 186.A security analyst is investigating a suspected data exfiltration incident. They are reviewing NetFlow records for a server in the DMZ that unexpectedly communicated with a foreign IP address for an extended period. The NetFlow records show a single, long-duration flow with a very high byte count transmitted from the internal server to the external IP, primarily using TCP port 443. What is the most likely exfiltration technique being used?Network Intrusion Analysis
  37. 187.A security analyst is reviewing network traffic logs and observes a high volume of TCP SYN packets originating from a single source IP address targeting a web server, but no corresponding SYN-ACK or ACK packets are being returned. The source IP address appears to be spoofed. Which type of attack is most likely occurring?Network Intrusion Analysis
  38. 188.An organization is conducting a security audit. The auditor discovers that several employees have elevated access privileges that are no longer required for their current job roles. This finding indicates a failure in adhering to which fundamental security principle?Security Policies and Procedures
  39. 189.A security analyst is reviewing network logs and discovers multiple failed login attempts from an external IP address targeting a critical internal server. The organization's incident response plan outlines specific steps for validating, categorizing, and escalating such events. Which phase of the incident response process is the analyst currently engaged in?Security Policies and Procedures
  40. 190.A security analyst is reviewing logs from a web application firewall (WAF) and notices a high volume of requests containing unusual characters and syntax in the URL parameters, specifically single quotes, double dashes, and 'OR 1=1' constructions. These requests are directed at a login page. What type of attack is the WAF most likely detecting?Network Intrusion Analysis
  41. 191.A security operations center (SOC) analyst is investigating an alert from a Security Information and Event Management (SIEM) system. The alert indicates a significant increase in failed login attempts against a critical internal database server, originating from a single internal IP address. The attempts are occurring rapidly and systematically trying different username/password combinations. Which type of attack is most likely underway?Network Intrusion Analysis
  42. 192.A small business is developing its first set of security policies. They are concerned about employees accidentally downloading malware from untrusted websites. Which type of policy would be most effective in guiding employee behavior to mitigate this specific risk?Security Policies and Procedures
  43. 193.A security analyst needs to capture network traffic on a segment for forensic analysis without introducing any latency or becoming a single point of failure. The current network switch only supports port mirroring (SPAN). What is the most appropriate and robust hardware solution to achieve this goal?Network Intrusion Analysis
  44. 194.A security auditor is performing an assessment of an organization's compliance with regulatory requirements. The auditor observes that a new system has been deployed without going through the standard security review and approval process outlined in the organization's security procedure documentation. Which aspect of the security program is primarily being evaluated by this observation?Security Policies and Procedures
  45. 195.A security analyst is investigating a suspected data exfiltration incident. They are reviewing network traffic logs and observe encrypted traffic leaving the internal network destined for an unusual external IP address on port 443. However, upon deeper inspection, the certificate presented by the external server is self-signed and the traffic pattern (small, sporadic bursts) is inconsistent with typical web browsing or legitimate encrypted data transfers. What is the most likely method of data exfiltration?Network Intrusion Analysis
  46. 196.A security analyst is investigating an alert from an Intrusion Detection System (IDS) indicating a potential buffer overflow attempt on a web server. The alert details mention unusually long strings of non-alphanumeric characters, including a sequence of 'A's followed by what appears to be shellcode, being sent in a POST request to a CGI script. What specific type of network intrusion is the IDS detecting?Network Intrusion Analysis
  47. 197.A security analyst is reviewing network traffic and observes repeated, small, encrypted packets being sent from an internal host to an external IP address on a non-standard port (e.g., 53, 443, or 80) at regular intervals, even when there is no user activity. The destination IP address is not associated with any known legitimate services used by the organization. What type of network intrusion activity is most likely indicated by this behavior?Network Intrusion Analysis
  48. 198.A security analyst is reviewing a packet capture from an internal network segment. They observe a high volume of ARP requests and replies, where multiple MAC addresses are being associated with a single IP address, and vice-versa. This is causing intermittent connectivity issues for several users on the segment. What type of attack is most likely occurring?Network Intrusion Analysis
  49. 199.A security analyst is investigating a compromised Linux server. They discover persistent outbound connections to an external IP address on TCP port 53. Upon analysis of the packet payload, they find that the data within the DNS queries and responses is highly unusual, containing long, encoded strings that do not resemble legitimate domain names or DNS records, but rather base64 encoded data. What type of covert communication channel is being used?Network Intrusion Analysis
  50. 200.A security analyst is investigating a series of alerts from an Intrusion Detection System (IDS) indicating unusual outbound ICMP traffic from several internal workstations to external IP addresses. The ICMP packets contain unusually large data payloads that do not correspond to standard diagnostic messages. What type of network intrusion technique is most likely being employed?Network Intrusion Analysis