Cisco CyberOps Associate (CBROPS) 200-201 practice questions

239 free questions with answers and explanations.

Practice test
  1. 201.A security team is implementing a new patch management procedure. The procedure dictates that all critical security patches must be applied to production servers within 72 hours of release, followed by a mandatory system reboot. Which characteristic of an effective security procedure is best demonstrated by this example?Security Policies and Procedures
  2. 202.A security analyst is reviewing network logs and discovers multiple failed login attempts from an external IP address targeting a critical internal server. The organization's incident response plan outlines specific steps for validating, categorizing, and escalating such events. Which phase of the incident response process is the analyst currently engaged in?Security Policies and Procedures
  3. 203.A security analyst is performing a network forensic investigation. The analyst needs to reconstruct a series of HTTP requests and responses from a PCAP file to understand user activity and potential data exfiltration. Which command-line tool is specifically designed for extracting and reassembling TCP/IP streams, including HTTP conversations, from a PCAP?Network Intrusion Analysis
  4. 204.A security analyst needs to capture network traffic on a segment for forensic analysis without introducing any latency or becoming a single point of failure. The current network switch only supports port mirroring (SPAN). What is the most appropriate and robust hardware solution to achieve this goal?Network Intrusion Analysis
  5. 205.A small business is developing its first set of security policies. They are concerned about employees accidentally downloading malware from untrusted websites. Which type of policy would be most effective in guiding employee behavior to mitigate this specific risk?Security Policies and Procedures
  6. 206.A SOC analyst is investigating a Windows endpoint where an Endpoint Detection and Response (EDR) solution has flagged a 'Suspicious Parent-Child Process Relationship' alert. The alert indicates that 'cmd.exe' was spawned by 'winword.exe', and subsequently 'powershell.exe' was spawned by 'cmd.exe'. The analyst needs to determine the full command-line arguments used for the 'powershell.exe' process. Which of the following Windows event logs and Event IDs should the analyst prioritize to find this specific information?Host-Based Analysis
  7. 207.A security analyst is investigating a potential compromise on a Windows server where an attacker is suspected of using a 'living off the land' (LotL) technique. Specifically, the attacker is believed to have used `certutil.exe` to download a malicious payload. Which command-line argument, when used with `certutil.exe`, is indicative of its misuse for file download purposes?Host-Based Analysis
  8. 208.A security analyst is performing host-based forensics on a Linux server after a suspected compromise. The analyst discovers an unfamiliar executable file in a /tmp directory that has been running for an extended period. To determine if this executable is indeed malicious and to understand its behavior, which of the following host-based analysis techniques would provide the most immediate and comprehensive insight without altering the live system significantly?Host-Based Analysis
  9. 209.An organization is deploying a new host-based intrusion detection system (HIDS) across its Windows server environment. The security team wants to ensure the HIDS is configured to detect unauthorized modifications to critical system files and registry keys, which are common tactics for persistence and privilege escalation. Which HIDS capability is primarily responsible for monitoring and alerting on these types of changes?Host-Based Analysis
  10. 210.A security analyst is reviewing a host-based intrusion detection system (HIDS) alert that indicates a critical system file (`C:\Windows\System32\ntoskrnl.exe`) has had its hash value changed. The HIDS uses a pre-established baseline for comparison. This type of alert most directly signifies a potential:Host-Based Analysis
  11. 211.A security analyst is investigating a Windows workstation that is exhibiting unusual network activity and process behavior. The analyst suspects a sophisticated malware infection. Which of the following host-based tools is best suited for identifying hidden processes, kernel-mode rootkits, and injected code on a live Windows system?Host-Based Analysis
  12. 212.A security analyst is investigating a compromised Linux server and suspects the attacker has manipulated dynamic linker preloading (LD_PRELOAD) to redirect system calls for malicious purposes. Which of the following host-based forensic steps would be most effective in identifying if LD_PRELOAD is being used by a running process?Host-Based Analysis
  13. 213.A security analyst is investigating a Windows workstation that is exhibiting unusual network activity, including frequent connections to an unknown external IP address. The analyst suspects a persistent malware infection. Which of the following host-based artifacts would be most indicative of a malware establishing persistence through a service?Host-Based Analysis
  14. 214.A security analyst is investigating a Windows workstation where sensitive data is suspected to have been exfiltrated. The attacker likely used living-off-the-land binaries (LOLBINs) to avoid detection. The analyst needs to identify unusual command-line executions that might indicate the use of such tools for data staging or exfiltration. Which of the following host-based logging configurations would be most critical to enable for this investigation?Host-Based Analysis
  15. 215.A security analyst is investigating a suspected malware infection on a Windows workstation. Initial scans by the endpoint detection and response (EDR) solution have flagged several suspicious processes, but no definitive malicious payload has been identified. The analyst wants to understand the behavior of one particular process, `svchost.exe`, which is showing unusual network activity. Which host-based analysis technique would be most effective for gaining deeper insight into this process's actions without directly interacting with the potentially compromised system?Host-Based Analysis
  16. 216.A security analyst is investigating a suspected zero-day malware infection on a critical Windows server. The EDR solution has detected highly unusual process behavior, including a legitimate system process (`svchost.exe`) making outbound connections to a malicious IP address and creating unusual child processes. Which endpoint security technology is specifically designed to identify and block such novel, behavior-based threats that lack known signatures?Host-Based Analysis
  17. 217.A security analyst is investigating an alert from an endpoint protection platform (EPP) indicating a suspicious PowerShell script executed on a Windows server. The EPP reported that the script attempted to disable Windows Defender and establish a persistent network connection. To understand the full scope of the script's actions and potential impact, which host-based artifact would provide the most comprehensive detail about the script's execution, including its arguments, execution path, and any child processes it spawned?Host-Based Analysis
  18. 218.A security operations center (SOC) analyst is investigating an alert from an Endpoint Detection and Response (EDR) system indicating a suspicious process injection on a Windows server. The alert points to a legitimate svchost.exe process exhibiting unusual child processes and network connections. To further investigate this, the analyst needs to capture detailed information about the affected process and its memory. Which of the following tools or techniques is most appropriate for acquiring a memory dump of a specific process on a live Windows system for offline analysis?Host-Based Analysis
  19. 219.A security analyst is investigating a Windows server that was recently involved in a data exfiltration incident. The attacker is believed to have used a living-off-the-land binary (LOLBIN) to compress and stage data before exfiltration. The analyst needs to identify if and how 'makecab.exe' was used. Which of the following host-based artifacts would be most critical for determining the command-line arguments passed to 'makecab.exe'?Host-Based Analysis
  20. 220.A security analyst is performing host-based intrusion detection on a critical Linux web server. They want to monitor for unauthorized modifications to core system binaries (e.g., /bin/ls, /usr/bin/sudo) in real-time. Which host-based security technology would be most effective for detecting such changes immediately?Host-Based Analysis
  21. 221.A forensic investigator is analyzing a Linux server after a suspected compromise. The attacker is believed to have modified system binaries to maintain persistence and evade detection. Which of the following commands would be most effective for verifying the integrity of installed packages against their original state on a Debian-based system?Host-Based Analysis
  22. 222.A forensic investigator is examining a compromised Windows workstation. They suspect that a malicious actor used a tool to dump user credentials from memory. To confirm this, the investigator needs to analyze the contents of the system's physical memory. Which tool is commonly used in host-based forensics to acquire a complete image of volatile memory for offline analysis?Host-Based Analysis
  23. 223.A security analyst is investigating a Windows endpoint where an advanced persistent threat (APT) is suspected. The attacker is believed to be maintaining control using a sophisticated mechanism that modifies the Windows Kernel to hide processes and network connections. Standard user-mode tools (like Task Manager, netstat, etc.) show no anomalies. Which of the following host-based forensic techniques would be most effective in detecting such a kernel-mode rootkit?Host-Based Analysis
  24. 224.A security analyst is performing a host-based investigation on a server that was recently compromised. During the analysis, the analyst discovers several scheduled tasks that were created by an unknown user, configured to run PowerShell scripts at regular intervals. Which common malware persistence mechanism does this scenario most clearly represent?Host-Based Analysis
  25. 225.A security analyst is investigating an alert from an Endpoint Detection and Response (EDR) solution indicating 'Suspicious Registry Modification' on a Windows workstation. The alert specifically points to a change in the 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify' key. What does a malicious modification to this specific Registry key typically indicate?Host-Based Analysis
  26. 226.A security analyst is investigating a Windows workstation exhibiting signs of compromise, including unusual system crashes and blue screens of death (BSODs). The analyst suspects a kernel-mode rootkit has been installed. Which of the following host-based analysis techniques is most effective for detecting kernel-mode rootkits that hide processes, files, or network connections by directly manipulating kernel data structures?Host-Based Analysis
  27. 227.A security analyst is performing host-based forensics on a Linux workstation. The workstation is suspected of being compromised by a rootkit that hides malicious processes. Which command-line utility, by inspecting kernel-level structures, is specifically designed to detect hidden processes that standard tools like `ps aux` might not reveal?Host-Based Analysis
  28. 228.A security analyst receives an alert from an EDR solution indicating a 'Suspicious Parent-Child Process Relationship' on a critical server. The alert details show `cmd.exe` spawning `powershell.exe`, which then executes an encoded command, all originating from an unexpected user context. To quickly pivot and investigate other potential indicators of compromise (IOCs) related to this specific event across other endpoints, which type of data, commonly collected by EDR, would be most valuable for a centralized search?Host-Based Analysis
  29. 229.A security analyst is conducting a malware analysis of a suspicious executable found on a Windows endpoint. The goal is to determine if the malware attempts to establish persistence by modifying the Windows Registry. Which specific registry key path is a common target for malware to ensure execution upon system startup for the currently logged-on user?Host-Based Analysis
  30. 230.A security operations center (SOC) analyst is investigating a potential data exfiltration attempt from an internal server. The server's endpoint detection and response (EDR) agent has alerted on unusual outbound network connections from a non-standard process. To confirm if sensitive data has left the system, which specific host-based log file or event type on a Linux server would provide the most direct evidence of file access and transfer, specifically relating to the process's actions?Host-Based Analysis
  31. 231.A security analyst is investigating a Linux system where a user's account was compromised. The attacker is believed to have used a privilege escalation exploit and then tried to cover their tracks by deleting critical log files. Which of the following host-based forensic artifacts, if present, would provide the most resilient evidence of the attacker's commands, even if 'bash_history' and common system logs were cleared?Host-Based Analysis
  32. 232.A security analyst is performing host-based forensics on a Linux server following a suspected compromise. The attacker is believed to have tampered with system binaries to maintain backdoor access and evade detection. Which command-line utility is most effective for verifying the integrity of installed packages and system binaries against known good checksums or cryptographic hashes?Host-Based Analysis
  33. 233.A security analyst is investigating a Linux workstation from which sensitive intellectual property was exfiltrated. The attacker is suspected of having deleted their tracks using 'shred' or 'rm -rf' commands. To determine if specific files were deleted and potentially recover their names, which of the following host-based forensic artifacts would be most valuable to examine, assuming the attacker could not overwrite the entire disk?Host-Based Analysis
  34. 234.A security analyst is performing host-based analysis on a Windows system suspected of being compromised by a new, unknown malware variant. The analyst wants to capture a full memory dump of the system for later offline analysis. Which of the following considerations is most critical when performing memory acquisition on a live system to ensure forensic soundness?Host-Based Analysis
  35. 235.A forensic investigator is analyzing a compromised Linux server and finds evidence of unauthorized root access. They suspect a kernel-level rootkit has been installed. Which of the following tools or techniques would be most effective in detecting a sophisticated kernel-level rootkit that might hide its presence from standard system utilities?Host-Based Analysis
  36. 236.A security analyst is reviewing the organization's current access control policies. They notice that several employees, who have recently transferred departments, still retain elevated permissions from their previous roles, despite no longer requiring them. This scenario represents a direct violation of which security principle?Security Policies and Procedures
  37. 237.A security analyst is investigating alerts from a host-based intrusion detection system (HIDS) indicating multiple failed login attempts against a critical server. Upon further review of the server's authentication logs, they observe that these attempts are originating from various IP addresses globally, but all are targeting a small number of valid usernames. Which type of attack is most likely occurring?Security Monitoring
  38. 238.A security operations center (SOC) analyst is investigating an alert indicating high network latency and intermittent connectivity issues on a critical internal server. Reviewing network traffic, the analyst observes a large volume of malformed UDP packets originating from various external IP addresses targeting random high-numbered ports on the server. There is no established session, and the server is responding with ICMP Destination Unreachable messages. Which type of attack is most likely occurring?Network Intrusion Analysis
  39. 239.A security analyst is investigating a compromised workstation that was communicating with an external IP address over port 53. Further inspection of the packet capture reveals that the DNS queries are unusually long and contain seemingly random alphanumeric strings within the query name, often followed by a known malicious domain. The responses are also non-standard, containing encoded data. What type of covert communication channel is this likely indicative of?Network Intrusion Analysis