Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Cisco Understanding Cisco Cybersecurity Operations Fundamentals 200-201 Exam Questions

Page: 1 / 32 Total 476 questions

Want more questions? Get Premium Access.

Question 1

An organization is cooperating with several third-party companies. Data exchange is on an unsecured channel using port 80 Internal employees use the FTP service to upload and download sensitive data An engineer must ensure confidentiality while preserving the integrity of the communication. Which technology must the engineer implement in this scenario'?

Correct Answer: A. X 509 certificates
Explanation:

To ensure confidentiality while preserving the integrity of communication when exchanging data over unsecured channels (port 80) and using FTP for sensitive data, the engineer must implement:

  • SFTP (SSH File Transfer Protocol): Encrypts the entire FTP session including authentication credentials, commands, and data transfer, providing both confidentiality and integrity.
  • TLS/SSL: Can be used to encrypt the communication channel, or implement FTPS (FTP over SSL/TLS).

These technologies encrypt the data in transit, ensuring that sensitive information cannot be intercepted or modified during transmission, which addresses both confidentiality and integrity requirements.

Question 2

Which statement describes indicators of attack?

Correct Answer: A. internal hosts communicate with countries outside of the business range.
Explanation:

Indicators of Attack (IoA) refer to observable behaviors or artifacts that suggest a security breach or ongoing attack.

When internal hosts communicate with countries outside the business range, it may indicate data exfiltration or command-and-control communication to an external threat actor.

Unlike Indicators of Compromise (IoC) which indicate that a system has already been compromised, IoAs are often used to identify malicious activity in its early stages.

Monitoring for unusual outbound connections is a crucial aspect of detecting advanced persistent threats (APTs) and other sophisticated attacks.

Reference

Difference Between Indicators of Compromise and Indicators of Attack

Cyber Threat Detection Using Indicators of Attack

Network Monitoring for Anomalous Behavior


Question 3

Which evasion method is being used when TLS is observed between two endpoints?

Correct Answer: B. Encryption
Explanation:

When TLS (Transport Layer Security) is observed between two endpoints, the evasion technique being employed is encryption. TLS encrypts all communications between the endpoints, making the traffic contents invisible to network monitoring tools and analysts. This prevents inspection of the actual data being transmitted, allowing malicious activities to hide within legitimate-looking encrypted channels. This is commonly used by threat actors to evade detection by IDS/IPS systems and deep packet inspection (DPI) mechanisms.

Question 4

What is the difference between authentication and authorization?

Correct Answer: D. Authentication allows an engineer to identify who can connect to a router, and authorization is the function of specifying access rights and privileges to resources.
Explanation:

Authentication is the process of verifying that a user is who they claim to be. It involves validating credentials (username/password, biometrics, certificates, etc.) to confirm identity.

Authorization is the process of determining what an authenticated user is allowed to do. It defines what resources they can access and what actions they can perform based on their permissions and roles.

Example: Authentication is proving you are John Smith by providing a valid password. Authorization is determining whether John Smith can access the financial reports folder.

Question 5

An engineer is analyzing a recent breach where confidential documents were altered and stolen by the receptionist. Further analysis shows that the threat actor connected an externa USB device to bypass security restrictions and steal dat

a. The engineer could not find an external USB device Which piece of information must an engineer use for attribution in an investigation?

Question 6

Refer to the exhibit.

Refer to the exhibit. A security engineer receives several alerts from the SNORT IPS/IDS reporting malicious traffic. What should the engineer understand by examining the SNORT logs?

Correct Answer: C. A remote threat performs an EternalBlue attack on several hosts and different ports.

Question 7

Which difficulty occurs when log messages are compared from two devices separated by a Layer 3 device that performs Network Address Translation?

Correct Answer: D. IP addresses in the log messages do not match
Explanation:

When log messages from two devices separated by a Layer 3 device performing Network Address Translation (NAT) are compared, the difficulty is that IP addresses will be translated. The source or destination IP addresses appearing in logs from the two sides of the NAT device will differ because the NAT device rewrites the IP headers. This makes it difficult to correlate logs across the NAT boundary since the same communication will show different IP addresses depending on which side of the NAT you're observing. This complicates forensic analysis and troubleshooting.

Question 8

An automotive company provides new types of engines and special brakes for rally sports cars. The company has a database of inventions and patents for their engines and technical information Customers can access the database through the company's website after they register and identify themselves. Which type of protected data is accessed by customers?

Correct Answer: A. IP data
Explanation:

IP data stands for Intellectual Property data, which is any data that represents the creations of the mind, such as inventions, patents, designs, or artistic works. IP data is protected by law and has commercial value for its owners. In this case, the automotive company has a database of IP data for their engines and technical information, which customers can access after they register and identify themselves.Reference:= Cisco Cybersecurity Operations Fundamentals, Module 1: Security Concepts, Lesson 1.2: Data Protection, Topic 1.2.1: Data Types


Question 9

What is the difference between the ACK flag and the RST flag in the NetFlow log session?

Correct Answer: D. The ACK flag confirms the receipt of the prior segment, and the RST flag allows for the spontaneous termination of a connection
Explanation:

In NetFlow log sessions within TCP connections; ACK flag is used for acknowledging that data has been successfully received while RST flag is used when there's an error or when closing a connection spontaneously without following standard procedures.Reference:= Cisco Cybersecurity source documents or study guide


Question 10

What is a difference between SIEM and SOAR?

Question 11

What are the two characteristics of the full packet captures? (Choose two.)

Question 12

When an event is investigated, which type of data provides the investigate capability to determine if data exfiltration has occurred?

Correct Answer: A. full packet capture
Explanation:

Full packet capture provides the complete recording of all the packets that are transmitted over the network. This data is essential for in-depth analysis during an investigation, as it allows investigators to reconstruct the session, observe the content of the traffic, and determine if data exfiltration has occurred.


Question 13

What are indicators of attack?

Correct Answer: D. suspicious registry or system file changes
Explanation:

Indicators of Attack (IOA) are observable signs and evidence of actual attack techniques, tactics, or tools being used against a system or network. They represent active compromise activities rather than just potential vulnerabilities. IOAs include suspicious process execution, network connections to known malicious IPs, file modifications, registry changes, and behavioral patterns consistent with known attack methodologies. IOAs help SOC teams detect ongoing incidents, distinguish between reconnaissance and active attacks, and respond to threats in real-time.

Question 14

Which action should be taken if the system is overwhelmed with alerts when false positives and false negatives are compared?

Question 15

A multinational organization uses a complex network infrastructure incorporating multiple cloud services, diverse endpoints, and distributed networks with several security devices. Which challenge will the security team face when ensuring robust data visibility for effective threat detection and response?

Correct Answer: A. inconsistent data aggregation from different technologies used within the organization
Explanation:

In modern enterprise environments, organizations rely on a wide range of technologies, including cloud platforms, on-premises systems, endpoint tools, and network security devices. One of the primary challenges in such environments is inconsistent data aggregation across these heterogeneous technologies.

Different tools generate logs in varying formats, structures, and levels of detail. Normalizing, correlating, and aggregating this data into a unified view is complex and often requires significant effort, tooling, and tuning. Without consistent aggregation, security teams struggle to correlate events across systems, detect advanced threats, and build a complete incident timeline.

While different protocols, duplicate alerts, and retention limits are valid concerns, they are secondary effects of poor data aggregation. Cybersecurity operations documentation consistently identifies data normalization and aggregation as foundational challenges in large, distributed environments.