  1. Books + Practice
  2. Video tutorial + practice
  3. Online training + practice
  4. Offline training (Choose based on your location)

Question 1:

An analyst is exploring the functionality of different operating systems.

What is a feature of Windows Management Instrumentation that must be considered when deciding on an operating system?

A. queries Linux devices that have Microsoft Services for Linux installed

B. deploys Windows Operating Systems in an automated fashion

C. is an efficient tool for working with Active Directory

D. has a Common Information Model, which describes installed hardware and software

Correct Answer: D

Question 2:

Which two measures are used by the defense-in-depth strategy? (Choose two.)

A. Bridge the single connection into multiple.

B. Divide the network into parts.

C. Split packets into pieces.

D. Implement the patch management process.

E. Reduce the load on network devices.

Correct Answer: BD

Question 3:

Which type of data collection requires the largest amount of storage space?

A. alert data

B. transaction data

C. session data

D. full packet capture

Correct Answer: D

Question 4:

Refer to the exhibit.

Cisco 200-201 CBROPS latest exam practice materials questions 4

A suspicious IP address is tagged by Threat Intelligence as a brute-force attempt source. After the attacker produces many failed login entries it successfully compromises the account. Which stakeholder is responsible for the incident response detection step?

A. employee 2

B. employee 3

C. employee 4

D. employee 5

Correct Answer: C

Question 5:

What is a Shellshock vulnerability?

A. command injection

B. Cross-site scripting

C. heap overflow

D. SQL injection

Correct Answer: A

Question 6:

Which data format is the most efficient to build a baseline of traffic seen over an extended period?

A. syslog messages

B. full packet capture

C. NetFlow

D. firewall event logs

Correct Answer: C

Question 7:

How does certificate authority impact a security system?

A. It authenticates client identity when requesting an SSL certificate

B. It validates the domain identity of an SSL certificate

C. It authenticates domain identity when requesting an SSL certificate

D. It validates client identity when communicating with the se

Correct Answer: B

Question 8:

Refer to the exhibit.

Cisco 200-201 CBROPS latest exam practice materials questions 8

Which packet contains a file that is extractable within Wireshark?

A. 2317

B. 1986

C. 2318

D. 2542

Correct Answer: D

Question 9:

Which type of data consists of connection level, application-specific records generated from network traffic?

A. transaction data

B. location data

C. statistical data

D. alert data

Correct Answer: A

Question 10:

Which of these describes SOC metrics about security incidents?

A. time it takes to detect the incident

B. time it takes to assess the risks of the incident

C. probability of outage caused by the incident

D. probability of compromise and impact caused by the incident

Correct Answer: A

Question 11:

Refer to the exhibit.

Cisco 200-201 CBROPS latest exam practice materials questions 11

What is depicted in the exhibit?

A. Windows Event logs

B. Apache logs

C. IIS logs

D. UNIX-based syslog

Correct Answer: B

Question 12:

What are two social engineering techniques? (Choose two.)

A. privilege escalation

B. DDoS attack

C. phishing

D. man-in-the-middle

E. pharming

Correct Answer: CE

Question 13:

What specific type of analysis is assigning values to the scenario to see expected outcomes?

A. deterministic

B. exploratory

C. probabilistic

D. descriptive

Correct Answer: A

Question 14:

What is the difference between an inline and a tap mode traffic monitoring?

A. Inline monitors traffic without examining other devices, while a tap mode tags traffic and examines the data from monitoring devices.

B. Tap mode monitors traffic direction, while inline mode keeps packet data as it passes through the monitoring devices.

C. Tap mode monitors packets and their content with the highest speed, while the inline mode draws a packet path for analysis.

D. Inline mode monitors traffic path, examining any traffic at a wire speed, while tap mode monitors traffic as it crosses the network.

Correct Answer: D

Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/650/configuration/guide/fpmc-config-guide-v65/inline_sets_and_passive_interfaces_for_firepower_threat_defense.html

Question 15:

What is a scareware attack?

A. inserting malicious code that causes popup windows with flashing colors

B. overwhelming a targeted website with fake traffic

C. gaining access to your computer and encrypting data stored on it

D. using the spoofed email addresses to trick people into providing login credentials

Correct Answer: A

