[Nov 21, 2025] Get Free Updates Up to 365 days On Developing 200-201 Braindumps
Best Quality Cisco 200-201 Exam Questions
Cisco 200-201 exam consists of 100 questions, which must be completed within 120 minutes. 200-201 exam is available in multiple languages, including English, Japanese, and Spanish. It is a computer-based exam that can be taken at Pearson VUE testing centers or online through the Pearson OnVUE platform.
Cisco 200-201 exam covers a wide range of topics, including security concepts, network security, endpoint protection, threat analysis, incident response, and vulnerability management. 200-201 exam consists of 60-70 questions and candidates have 90 minutes to complete it. To pass the exam, candidates must score at least 750 out of 1000 points.
NEW QUESTION # 80
What is the difference between the ACK flag and the RST flag in the NetFlow log session?
- A. The RST flag confirms the beginning of the TCP connection, and the ACK flag responds when the data for the payload is complete
- B. The RST flag confirms the receipt of the prior segment, and the ACK flag allows for the spontaneous termination of a connection
- C. The ACK flag confirms the beginning of the TCP connection, and the RST flag responds when the data for the payload is complete
- D. The ACK flag confirms the receipt of the prior segment, and the RST flag allows for the spontaneous termination of a connection
Answer: D
Explanation:
In NetFlow log sessions within TCP connections; ACK flag is used for acknowledging that data has been successfully received while RST flag is used when there's an error or when closing a connection spontaneously without following standard procedures. References := Cisco Cybersecurity source documents or study guide
NEW QUESTION # 81
Refer to the exhibit.
What must be interpreted from this packet capture?
- A. IP address 192.168.88.12 is communicating with 192 168 88 149 with a source port 49098 to destination port 80 using TCP protocol.
- B. IP address 192.168.88.149 is communicating with 192.168 88.12 with a source port 80 to destination port 49098 using TCP protocol.
- C. IP address 192.168.88.149 is communicating with 192.168.88.12 with a source port 49098 to destination port 80 using TCP protocol.
- D. IP address 192.168.88 12 is communicating with 192 168 88 149 with a source port 74 to destination port 49098 using TCP protocol
Answer: B
Explanation:
The packet capture shows that IP address 192.168.88.149, using source port 80 (common for HTTP traffic), initiated communication with IP address 192.168.88.12 at destination port 49098, using the TCP protocol, indicating a typical client-server interaction over the web.
NEW QUESTION # 82
Which step in the incident response process researches an attacking host through logs in a SIEM?
- A. eradication
- B. preparation
- C. detection and analysis
- D. containment
Answer: C
Explanation:
In the incident response process, detection and analysis involve researching an attacking host through logs in a Security Information and Event Management (SIEM) system. This step helps in identifying, validating, and managing potential security incidents. Reference:= Cisco CyberOps Associate - Module 3: Security Monitoring
NEW QUESTION # 83
Drag and drop the type of evidence from the left onto the description of that evidence on the right.
Answer:
Explanation:
Explanation:
Graphical user interface, application Description automatically generated
NEW QUESTION # 84
Which two elements are used for profiling a network? (Choose two.)
- A. running processes
- B. OS fingerprint
- C. listening ports
- D. session duration
- E. total throughput
Answer: C,E
Explanation:
Profiling a network involves various elements that provide insights into its characteristics and behaviors. Total throughput is crucial as it measures the amount of data passing from a source to a destination in a given period, reflecting the network's capacity and usage patterns1. Listening ports are also essential for profiling because they represent the entry points for network services, indicating which services are available and potentially vulnerable1.
References :=
* Network profiling tools and techniques discussed in online resources23.
* Direct explanations of network profile elements
NEW QUESTION # 85
Which two components reduce the attack surface on an endpoint? (Choose two.)
- A. full packet captures at the endpoint
- B. secure boot
- C. load balancing
- D. increased audit log levels
- E. restricting USB ports
Answer: B,E
NEW QUESTION # 86
An employee reports that someone has logged into their system and made unapproved changes, files are out of order, and several documents have been placed in the recycle bin. The security specialist reviewed the system logs, found nothing suspicious, and was not able to determine what occurred. The software is up to date; there are no alerts from antivirus and no failed login attempts. What is causing the lack of data visibility needed to detect the attack?
- A. The threat actor used the teardrop technique to confuse and crash login services.
- B. The threat actor gained access to the system by known credentials.
- C. The threat actor used a dictionary-based password attack to obtain credentials.
- D. The threat actor used an unknown vulnerability of the operating system that went undetected.
Answer: B
Explanation:
The lack of data visibility needed to detect the attack is caused by the threat actor gaining access to the system by known credentials. This means that the threat actor either obtained the employee's username and password through phishing, social engineering, or other means, or used a compromised account that had legitimate access to the system. This would explain why there were no suspicious logs, alerts, or failed login attempts, as the threat actor appeared to be a normal user. References: https://learningnetworkstore.cisco.com/on-demand- e-learning/understanding-cisco-cybersecurity-operations-fundamentals-cbrops-v1-0/CSCU-LP-CBROPS-V1-
028093.html (Module 2, Lesson 2.1.2)
NEW QUESTION # 87
Which attack method intercepts traffic on a switched network?
- A. denial of service
- B. ARP cache poisoning
- C. command and control
- D. DHCP snooping
Answer: D
NEW QUESTION # 88
A SOC analyst detected connections to known C&C and port scanning activity to main HR database servers from one of the HR endpoints via Cisco StealthWatch. What are the two next steps of the SOC team according to the NISTSP800-61 incident handling process? (Choose two)
- A. Isolate affected endpoints and take disk images for analysis
- B. Provide security awareness training to HR managers and employees
- C. Update antivirus signature databases on affected endpoints to block connections to C&C
- D. Detect the attack vector and analyze C&C connections
- E. Block connection to this C&C server on the perimeter next-generation firewall
Answer: A,E
Explanation:
According to the NIST SP 800-61 incident handling process, the SOC team should first isolate the affected endpoints to prevent further spread of the attack and take disk images for analysis (A). This helps in preserving evidence for a thorough investigation. The next step would be to block the connection to the C&C server on the perimeter next-generation firewall , which helps to cut off the communication between the compromised endpoint and the attacker's server, thereby mitigating the threat123.
The answers are based on the guidelines provided in the NIST SP 800-61 Computer Security Incident Handling Guide, which outlines the steps for incident handling, including detection, analysis, containment, eradication, recovery, and post-incident activities
NEW QUESTION # 89
What is session data used for in network security?
- A. It is the transaction log between monitoring software.
- B. It contains the set of parameters used for fetching logs.
- C. It tracks cookies within each session initiated from a user.
- D. It is the summary of the transmission between two network devices.
Answer: D
NEW QUESTION # 90
Refer to the exhibit.
Which type of log is displayed?
- A. NetFlow
- B. sys
- C. proxy
- D. IDS
Answer: A
Explanation:
The exhibit shows a log that contains information such as the date, flow start, duration, protocol used, source and destination IP addresses and ports, packets, bytes, and flows. This type of detailed metadata is typically associated with NetFlow logs which are used for collecting IP traffic information and monitoring network traffic. Reference := Cisco CyberOps Associate
NEW QUESTION # 91
Which artifact is used to uniquely identify a detected file?
- A. file size
- B. file timestamp
- C. file extension
- D. file hash
Answer: D
NEW QUESTION # 92 
Refer to the exhibit. What should be interpreted from this packet capture?
- A. IP address 179.179.69/50272/192.168.122.100/80/6 is sending a packet from port 50272 of IP address
192.168.122.100 that is going to port 80 of IP address 81.179.179.69 using IP protocol 6. - B. IP address 192.168.122.100/50272/81.179.179.69/80/6 is sending a packet from port 80 of IP address
192.168.122.100 that is going to port 50272 of IP address 81.179.179.69 using IP protocol 6. - C. IP address 192.168.122.100/50272/81.179.179.69/80/6 is sending a packet from port 50272 of IP address
192.168.122.100 that is going to port 80 of IP address 81.179.179.69 using IP protocol 6. - D. IP address 179.179.69/50272/192.168.122.100/80/6 is sending a packet from port 80 of IP address
192.168.122.100 that is going to port 50272 of IP address 81.179.179.69 using IP protocol 6.
Answer: C
Explanation:
Section: Security Monitoring
NEW QUESTION # 93
Refer to the exhibit.
Refer to the exhibit. Based on the .pcap file, which protocol's vulnerability has been exploited to establish a session?
- A. IP
- B. TCP
- C. Negotiate
- D. SMB
Answer: D
NEW QUESTION # 94
A security engineer has a video of a suspect entering a data center that was captured on the same day that files in the same data center were transferred to a competitor.
Which type of evidence is this?
- A. best evidence
- B. indirect evidence
- C. physical evidence
- D. prima facie evidence
Answer: B
NEW QUESTION # 95
Which vulnerability type is used to read, write, or erase information from a database?
- A. buffer overflow
- B. SQL injection
- C. cross-site scripting
- D. cross-site request forgery
Answer: B
NEW QUESTION # 96
An engineer is working on a ticket for an incident from the incident management team A week ago. an external web application was targeted by a DDoS attack Server resources were exhausted and after two hours it crashed. An engineer was able to identify the attacker and technique used Three hours after the attack, the server was restored and the engineer recommended implementing mitigation by Blackhole filtering and transferred the incident ticket back to the IR team According to NIST SP800-61, at which phase of the incident response did the engineer finish work?
- A. containment eradication and recovery
- B. preparation
- C. post-incident activity
- D. detection and analysis
Answer: A
Explanation:
According to NIST SP800-61, the incident response phase called "Containment, Eradication, and Recovery" involves containing the incident, eradicating the threat, and recovering from the incident2. In the scenario described, the engineer worked on containing the DDoS attack by identifying the attacker and the technique used, which is part of the containment process. The recommendation to implement Blackhole filtering is part of the eradication process, where measures are taken to prevent the attack from happening again. Finally, restoring the server is part of the recovery process, where normal operations are resumed. Therefore, the engineer finished work during the "Containment, Eradication, and Recovery" phase. Reference:: NIST SP800-61 Computer Security Incident Handling Guide2.
NEW QUESTION # 97
What is an advantage of symmetric over asymmetric encryption?
- A. A key is generated on demand according to data type.
- B. A one-time encryption key is generated for data transmission
- C. It is suited for transmitting large amounts of data.
- D. It is a faster encryption mechanism for sessions
Answer: D
Explanation:
Symmetric encryption is a type of encryption that uses the same key to encrypt and decrypt data. Asymmetric encryption is a type of encryption that uses a pair of keys: a public key and a private key. The public key can be used to encrypt data, but only the private key can decrypt it, and vice versa. An advantage of symmetric encryption over asymmetric encryption is that it is faster and more efficient for encrypting large amounts of data, such as in sessions or bulk transfers. Asymmetric encryption is slower and more computationally intensive, but it is more secure and suitable for key exchange or digital signatures. Reference:= Cisco Cybersecurity Operations Fundamentals, Module 2: Security Monitoring, Lesson 2.3: Cryptography and PKI, Topic 2.3.1: Cryptography
NEW QUESTION # 98
What is obtained using NetFlow?
- A. session data
- B. full packet capture
- C. network downtime report
- D. application logs
Answer: A
Explanation:
NetFlow is a network protocol developed by Cisco for collecting IP traffic information and monitoring network flow. It provides valuable data about the network sessions occurring within the network, such as source and destination IP addresses, port numbers, and protocols used. This session data is useful for understanding traffic patterns, volume, and usage.
NEW QUESTION # 99
Refer to the exhibit.
A suspicious IP address is tagged by Threat Intelligence as a brute-force attempt source After the attacker produces many of failed login entries, it successfully compromises the account. Which stakeholder is responsible for the incident response detection step?
- A. employee 5
- B. employee 2
- C. employee 4
- D. employee 3
Answer: C
NEW QUESTION # 100
When an event is investigated, which type of data provides the investigate capability to determine if data exfiltration has occurred?
- A. full packet capture
- B. NetFlow data
- C. firewall logs
- D. session data
Answer: A
Explanation:
Full packet capture provides the complete recording of all the packets that are transmitted over the network.
This data is essential for in-depth analysis during an investigation, as it allows investigators to reconstruct the session, observe the content of the traffic, and determine if data exfiltration has occurred.
NEW QUESTION # 101
An engineer received an alert affecting the degraded performance of a critical server Analysis showed a heavy CPU and memory load. What is the next step the engineer should take to investigate this resource usage?
- A. Run "ps -ef to understand which processes are taking a high amount of resources
- B. Run "ps -u" to find out who executed additional processes that caused a high load on a server
- C. Run "ps -m" to capture the existing state of daemons and map the required processes to find the gap
- D. Run "ps -d" to decrease the priority state of high-load processes to avoid resource exhaustion
Answer: A
Explanation:
When a server is experiencing heavy CPU and memory load, the initial step is to identify the processes consuming the most resources. The command "ps -ef" provides a detailed view of all running processes, including their IDs, CPU, and memory usage, which helps in pinpointing the resource-intensive processes1234. References: This approach is supported by various resources on server management and troubleshooting, which recommend using the "ps -ef" command as a starting point for investigating high resource usage on servers
NEW QUESTION # 102
Which NIST IR category stakeholder is responsible for coordinating incident response among various business units, minimizing damage, and reporting to regulatory agencies?
- A. public affairs
- B. management
- C. PSIRT
- D. CSIRT
Answer: B
Explanation:
In the context of NIST's incident response guidelines, management is responsible for coordinating incident response among various business units, minimizing damage, and reporting to regulatory agencies. Management plays a key role in overseeing the incident response process to ensure that it is carried out effectively across all parts of the organization and that compliance with legal and regulatory requirements is maintained12.
References :=
* NIST SP 800-61 Rev. 2, Computer Security Incident Handling Guide1.
* InfraExam's discussion on incident response stakeholder responsibilities
NEW QUESTION # 103
Drag and drop the technology on the left onto the data type the technology provides on the right.
Answer:
Explanation:

NEW QUESTION # 104
A SOC analyst is investigating an incident that involves a Linux system that is identifying specific sessions.
Which identifier tracks an active program?
- A. application identification number
- B. process identification number
- C. active process identification number
- D. runtime identification number
Answer: B
Explanation:
In the context of Linux systems, each active program is tracked using a process identification number (PID)
. The PID is a unique number that the system uses to refer to a specific process, which is an instance of an executed program. This allows the system and the SOC analyst to monitor and manage different processes, including those initiated by users, the system itself, or by applications.
References := Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS) training material provides insights into how a Security Operations Center (SOC) operates and the tools and data used by analysts to monitor and investigate security incidents, including the tracking of active programs on system
NEW QUESTION # 105
......
Cisco 200-201 exam, also known as Understanding Cisco Cybersecurity Operations Fundamentals, is a certification exam that tests the candidate's knowledge and skills in the field of cybersecurity operations. 200-201 exam is designed for individuals who are seeking to enhance their career in cybersecurity operations or looking to validate their skills in the field. It is an entry-level exam that covers the fundamental principles of cybersecurity operations, including security concepts, network infrastructure, and incident response.
Cisco Exam Practice Test To Gain Brilliante Result: https://certlibrary.itpassleader.com/Cisco/200-201-dumps-pass-exam.html