200-201 Practice Questions
Prepare for 200-201 with more than an answer.
Unlock the full exam and previous versions
- v1Standard 313 questions Current
- 210-250Legacy Cyber Ops Understanding Cisco Cybersecurity Fundamentals (SECFND) 220 questions Locked
- 210-255Legacy Implementing Cisco Cybersecurity Operations (SECOPS) 207 questions Locked
- Exam fee
- $300 USD
- Level
- Associate
- Valid for
- 3 years
Domains covered on the exam 5
- Security Concepts20%
- Security Monitoring25%
- Host-Based Analysis20%
- Network Intrusion Analysis20%
- Security Policies and Procedures15%
- 1
Which operation has as its goal the identification of all available services on a device?
Show answer details
Correct answer: A
Explanation: A port scan identifies the open ports on a device, and thus the services available.
A ping scan has as its goal identification of all live devices in the network. A smurf attack is an attack where a ping request is sent to a broadcast network address with the aim of overwhelming the system.
Operating system (OS) fingerprinting has as its goal the identification of the operating system and version. Banner grabbing is a fingerprinting technique that relies on morphed or empty TCP packets that are sent over to a target machine. Telnet, Netcat, Nmap and other tools can be used to carry out banner grabbing.
Banner grabbing also has as its goal the identification of the operating system and its version.
Banner grabbing intercepts a text file sent by a server or a host. The text file includes OS information and in the case of a web server, perhaps the basic configuration info. The attacker can then exploit that information.
Objective: Attack MethodsSub-Objective: Describe these endpoint-based attacks: Duffer overflows, Command and control (C2), Malware, Rootkit, Port scanning, Host Profiling -- Reference: https://www.lifewire.com/introduction-to-port-scanning-2486802
- 2
Which cross-site scripting attack is sometimes called persistent?
Show answer details
Correct answer: B
Explanation: A stored XSS attack is one in which the injected script is stored in the server and received from the server by the user device. Cross-site scripting (XSS) poses the most danger when a user accesses a financial organization’s site using his or her login credentials. The problem is not that the hacker will take over the server. It is more likely that the hacker will take over the client’s session. This will allow the hacker to gain information about the legitimate user that is not publicly available. To prevent XSS, a programmer should validate input to remove hypertext. You can mitigate XSS by preventing the use of HTML tags or JavaScript image tags.
A reflected or non-persistent attack is one that is reflected off the web server and not stored on the
server.
Directed is not a term used to describe cross site scripting attacks.
Objective: Attack Methods
Sub-Objective: Describe these web application attacks: SQL injection, Command injections,
Cross-site scripting
-- Reference: https://www.owasp.org/index.php/Cross-site_Scripting_(XSS)
- 3
Quantitative and qualitative are two types of which of the following?
Show answer details
Correct answer: A
Explanation: Risk analysis come in two basic types. When scoring is used to rate risks rather than dollar figures to potential outcomes.
A business impact analysis (BIA) focuses on critical business systems and the impact if they are lost to an outage. A BIA is created to identify the company’s vital functions and prioritize them based on need. It identifies vulnerabilities and threats and calculates the associated risks.
A disaster recovery plan is a short term plan that is implemented when a large disaster event occurs. The plan is created to ensure that your company can resume operations in a timelymanner. It mainly focuses on alternative procedures for processing transactions in the short term. it is carries out when the emergency occurs and immediately following the emergency.
Heuristics is an approach that identifies malware based on the behavior it exhibits rather than a signature. A heuristics IDS uses artificial intelligence (AI) to detect intrusions. Analytics are performed on the actions taken, and the IDS takes action based on the logic in the AI.Objective: Security ConceptsSub-Objective: Describe these security terms: Principle of least privilege, Risk scoring/risk weighting, Risk reduction, Risk assessment. -- Reference: https://www.pmi.org/learning/library/qualitative-risk-assessment-cheaper-faster-3188
- 4
What is the primary function of routers?
Show answer details
Correct answer: D
Explanation: Routers create both a broadcast domain for each interface. Routers move traffic from one network to another network, with each interface hosting an IP subnet. A router is a hardware device that transmits data among computers in different networks. Routers use IP addresses to make routing decisions.
A switch is a device that separates collision domains only. Switches make switching decisions based on MAC addresses. A switch is a high-speed networking device that receives incoming data
packets from one of its ports and directs them to a destination port for local area network access.
A switch will redirect traffic bound outside the local area to a router for forwarding through an appropriate WAN interface.
Neither routers nor switches create only a broadcast domain on each interface. Routers create both a broadcast domain and collision domain for each interface. A switch is a device that separates collision domain only.
DNS servers, not routers, separate DNS domains. A Domain Name Service (DNS) server provides a centralized database of domain name-to-IP address resolutions on a server that other computers on a network can use for name resolution.
Objective: Network Concepts
Sub-Objective: Describe the basic operation of these network device types: Router, Switch, Hub, Bridge, Wireless access point (WAP), Wireless LAN controller (WLC)
-- Reference: https://ciscoskills.net/2011/03/30/collision-domains-vs-broadcast-domains/
- 5
OpenDNS is a Cisco security solution designed to protect which component?
Show answer details
Correct answer: B
Explanation: OpenDNS is a company and service that hosts a cloud computing security product suite, Umbrella. OpenDNS’s business services were renamed as Cisco Umbrella; home productsretained the OpenDNS name. It also offers DNS resolution as an alternative to using Internet service providers’ DNS servers or locally installed DNS servers.
Other services offered for cloud protection by Cisco include Cloud lock.
While other products exist for LAN, WAN and DMZ, the Umbrella feature is not one of them.
A local area network (LAN) covers a small geographic area. Typically, a LAN is confined to a campus, a single building, a floor of a building, or an area with in building.
A wide area network (WAN) uses routers (or a collection of routers) to connect LANs that are dispersed over a large geographic area. An example would be a company with office locations in Boston, Miami, Chicago, Dallas, Denver, and San Francisco. Each office has its own LAN, and routers are used to provide connections between the offices. By building the WAN, the offices can share resources and data.
Objective: Network ConceptsSub-Objective: Describe the functions of these network security systems as deployed on the host, network, or the cloud: Firewall, Cisco Intrusion Prevention System (IPS), Cisco Advanced Malware Protection (AMP), Web Security Appliance (WSA) / Cisco Cloud Web Security (CWS, Email Security Appliance (ESA) / Cisco Cloud Email Security (CES). -- Reference: https://www.opendns.com/
- 6
Which type of algorithm encrypts data bit by bit?
Show answer details
Correct answer: C
Stream ciphers encrypt data bit by bit, processing one bit at a time continuously. This is in contrast to block ciphers which process fixed-size blocks of data. Stream ciphers use a keystream that is combined with plaintext bit by bit, making them ideal for real-time applications. Block ciphers process chunks of data, asymmetric algorithms use different keys for encryption/decryption, and symmetric is a broader category that includes both stream and block ciphers.
- 7
Which of the following is true of privilege escalation?
Show answer details
Correct answer: C
Privilege escalation occurs when someone obtains, without authorization, the rights and privileges of a different user or system. This typically happens when an attacker exploits vulnerabilities or misconfigurations to gain higher-level access than originally granted. Vertical movement refers to gaining higher privileges (like admin rights), while horizontal movement involves accessing resources at the same privilege level but in different contexts. The key aspect is that escalation happens without proper authorization.
- 8
Examine the diagram below, which contains all devices currently connected to Switch0.
Which of the following statements is true of this scenario?

Show answer details
Correct answer: D
Based on the network diagram shown in the image, the PCs are currently on different VLANs (VLAN 2 and VLAN 3) with different IP subnets, which prevents communication. To enable connectivity, both PCs must be on the same VLAN and same IP subnet. Changing Fa0/2 to VLAN 3 puts both PCs on the same VLAN, and changing PC1 IP to 192.168.6.5 puts them on the same subnet (192.168.6.0/24), allowing communication. Simply changing IP addresses without VLAN alignment or only changing VLANs without IP subnet alignment would not work.
- 9
Which of the following is deployed on an endpoint as an agent or standalone application?
Show answer details
Correct answer: C
A Host-based Intrusion Detection System (HIDS) is deployed directly on endpoints as an agent or standalone application to monitor individual workstations. HIDS monitors system calls, file integrity, registry changes, and local network activity on the specific host. Network-based IDS (NIDS) operates at the network level, NIPS (Network Intrusion Prevention System) is network-based, and NGFW (Next Generation Firewall) is a network perimeter device. Only HIDS is specifically designed for endpoint deployment.
- 10
Which of the following represents an exploitable, unpatched, and unmitigated weakness in software?
Show answer details
Correct answer: A
A vulnerability is an exploitable weakness in software or systems that has not been patched or mitigated. It represents a potential entry point for attackers but is not yet being actively exploited. An exploit is the actual method or code used to take advantage of a vulnerability, a threat is a potential danger, and a breach occurs when an attack successfully compromises a system. Vulnerabilities become dangerous when they remain unpatched and unmitigated, creating opportunities for exploitation.
