dc dotCreds
Cisco Certified Cybersecurity Associate (200-201 CCNACBR) Practice Test

Cisco CyberOps Associate Practice Test

Start today’s free 10-question Cisco CyberOps Associate set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 23, 2026, 8:12 PM CDT

Go Pro - One Time Unlock

Unlock the full 200-201 CCNACBR bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 Cisco CyberOps Associate questions

Use this Cisco CyberOps Associate practice test to review Cisco Certified Cybersecurity Associate. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective 3.2 Describe operating system components in Windows and Linux 3. Host-Based Analysis

A responder finds an unfamiliar value under a Windows autorun registry location that references a script in the user's profile. What does this artifact MOST strongly suggest?

Concept tested:
Question 2 of 10
Objective 2.3 Explain visibility impact of network technologies 2. Security Monitoring

A monitoring sensor sees GRE packets between two gateways, but the analyst cannot directly attribute the inner application conversation from outer-header fields alone. Why is attribution more difficult at that sensor?

Concept tested:
Question 3 of 10
Objective 5.8 Describe server profiling concepts 5. Security Policies and Procedures

A web server normally listens on TCP 443 and 22 and runs a small known set of services. A new process begins listening on TCP 4444 under an unfamiliar account. Which server-profiling comparison is MOST useful?

Concept tested:
Question 4 of 10
Objective 3.4 Identify evidence types 3. Host-Based Analysis

An application audit log directly records that account jsmith changed a payment-routing value at 14:03. A separate email shows the user discussing the change. Which item is the strongest direct evidence of the system action?

Concept tested:
Question 5 of 10
Objective 4.2 Compare true/false positives and negatives / benign events 4. Network Intrusion Analysis

An IDS alerts on an exploit signature. PCAP and host logs confirm the exploit reached the target and spawned a malicious process. How should the detection be classified?

Concept tested:
Question 6 of 10
Objective 1.7 Describe terms as defined in CVSS 1. Security Concepts

A vulnerability can be exploited only after the attacker authenticates with a low-privilege account, and successful exploitation also requires a victim to open a crafted file. Which CVSS Base metrics directly capture those prerequisites?

Concept tested:
Question 7 of 10
Objective 2.9 Describe evasion and obfuscation techniques 2. Security Monitoring

Malware connects to an external relay and has the relay communicate with the final command-and-control server, so the victim never connects directly to the final destination. How can the relay affect monitoring?

Concept tested:
Question 8 of 10
Objective 5.1 Describe management concepts 5. Security Policies and Procedures

Two servers built from the same approved image now differ because local administrators changed security settings over time. What problem is MOST clearly demonstrated?

Concept tested:
Question 9 of 10
Objective 3.1 Describe endpoint technologies in security monitoring 3. Host-Based Analysis

A process on a workstation tries to open an outbound TCP connection, but the local security log records a host-firewall rule blocking the connection before it leaves the endpoint. Which control generated the most directly relevant enforcement evidence?

Concept tested:
Question 10 of 10
Objective 4.5 Compare the characteristics of data obtained from taps and traffic monitoring 4. Network Intrusion Analysis

A NetFlow record confirms a long-lived HTTPS connection to a suspicious host but does not reveal the requested URI. Why can the URI not be determined from the flow record alone?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
200-201 CCNACBR Pro $4.99 one-time

50 Exam Practice Test $1.99 one-time

A 50-question 200-201 CCNACBR PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

Cisco Cybersecurity Bundle $9.99 one-time

Unlock all 3 active Cisco Cybersecurity Bundle practice banks in one permanent purchase.

What’s includedCCST Cybersecurity, Cisco Cybersecurity Associate, CCNA
All Access $6.99/month

Unlock every active practice exam, bundle and path experience, Pro course and study content, and included downloads.

What’s includedEvery current and future active practice exam, All active bundle and career-path practice content, Pro course lessons, study content, and supported paid downloads

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full 200-201 CCNACBR bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily 200-201 CCNACBR practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily Cisco CyberOps Associate set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 A responder finds an unfamiliar value under a Windows autorun registry location that references a script in the user's profile. What does this artifact MOST strongly suggest?

Answer choices

  1. A. A persistence mechanism that starts code at user logon
  2. B. A DNS cache-poisoning event, for the described technical objective and its associated operational control requirements.
  3. C. A network-only denial-of-service condition, for the stated security, delivery, and accountability requirements.
  4. D. A certificate revocation event, for the stated . host-based analysis requirement.

Correct answer

A persistence mechanism that starts code at user logon

Windows autorun registry locations can cause specified programs or scripts to execute during logon, making them relevant persistence artifacts.

Wrong-answer review

  • B. A DNS cache-poisoning event, for the described technical objective and its associated operational control requirements.: DNS cache poisoning concerns name-resolution data rather than local autorun configuration.
  • C. A network-only denial-of-service condition, for the stated security, delivery, and accountability requirements.: A DoS condition affects availability and does not explain the registry startup entry.
  • D. A certificate revocation event, for the stated . host-based analysis requirement.: Certificate revocation concerns PKI trust and is unrelated to a Run key.

Extra learning features

Interview question

Q: Windows autorun registry locations can cause specified programs or scripts to execute during logon, making them relevant persistence artifacts. Strong answer: The Windows autorun registry locations are a common method for persistence, allowing malware to automatically execute upon user logon.

  • Windows autorun registry locations
  • persistence artifacts
  • user logon

Caution: Do not restate the multiple-choice stem or ask the learner merely to name a product, rule, or term.

Why this matters

Understanding Windows autorun configuration is critical for identifying and mitigating persistent malware. Failure to recognize this artifact can lead to an attacker maintaining a foothold on the system, enabling further malicious activity and potentially causing significant data breaches or service disruptions. This directly impacts operational security and reduces the risk of compromise.

Objective/domain: 3. Host-Based Analysis

Source: Microsoft Windows Security Auditing Documentation

Question 2 A monitoring sensor sees GRE packets between two gateways, but the analyst cannot directly attribute the inner application conversation from outer-header fields alone. Why is attribution more difficult at that sensor?

Answer choices

  1. A. Tunneling or encapsulation can hide the inner conversation behind outer headers, for this requirement.
  2. B. The tunnel deletes all packets before monitoring, for the required operational result and control objective.
  3. C. Encapsulation guarantees malicious traffic cannot traverse the link, under the proposed approach.
  4. D. The sensor automatically learns every inner endpoint without decapsulation, in context.

Correct answer

Tunneling or encapsulation can hide the inner conversation behind outer headers, for this requirement.

Objective/domain: 2. Security Monitoring

Source: RFC 2784, Generic Routing Encapsulation (GRE)

Question 3 A web server normally listens on TCP 443 and 22 and runs a small known set of services. A new process begins listening on TCP 4444 under an unfamiliar account. Which server-profiling comparison is MOST useful?

Answer choices

  1. A. Compare current listening ports, accounts, processes, tasks, and applications with the known baseline, within the defined security and accountability boundaries.
  2. B. Compare only monitor color depth, for the described technical objective and its associated operational control requirements, for evaluation.
  3. C. Check only public DNS TTL, under the organization’s defined implementation and exception-management process.
  4. D. Ignore the new service if CPU usage is low, under the organization’s defined implementation and exception-management process.

Correct answer

Compare current listening ports, accounts, processes, tasks, and applications with the known baseline, within the defined security and accountability boundaries.

Objective/domain: 5. Security Policies and Procedures

Source: NIST SP 800-94, Guide to Intrusion Detection and Prevention Systems (IDPS)

Question 4 An application audit log directly records that account jsmith changed a payment-routing value at 14:03. A separate email shows the user discussing the change. Which item is the strongest direct evidence of the system action?

Answer choices

  1. A. The supporting email alone, for the stated requirement.
  2. B. A rumor from another employee, as the primary proposed approach.
  3. C. A generic threat report, within the defined security and accountability boundaries.
  4. D. The authoritative system audit record of the action, within the described operational context.

Correct answer

The authoritative system audit record of the action, within the described operational context.

Question 5 An IDS alerts on an exploit signature. PCAP and host logs confirm the exploit reached the target and spawned a malicious process. How should the detection be classified?

Answer choices

  1. A. False positive, for the required outcome.
  2. B. False negative
  3. C. True positive, for evaluation.
  4. D. True negative, for the specified implementation requirement.

Correct answer

True positive, for evaluation.

Objective/domain: 4. Network Intrusion Analysis

Source: NIST SP 800-94, Guide to Intrusion Detection and Prevention Systems (IDPS)

Question 6 A vulnerability can be exploited only after the attacker authenticates with a low-privilege account, and successful exploitation also requires a victim to open a crafted file. Which CVSS Base metrics directly capture those prerequisites?

Answer choices

  1. A. Attack Vector and Scope only, under the proposed approach.
  2. B. Environmental and Temporal only, for the required operational result and control objective.
  3. C. Privileges Required and User Interaction, as the organization’s selected response.
  4. D. Availability and Integrity only, as configured.

Correct answer

Privileges Required and User Interaction, as the organization’s selected response.

Objective/domain: 1. Security Concepts

Source: FIRST Common Vulnerability Scoring System v3.1 Specification

Question 7 Malware connects to an external relay and has the relay communicate with the final command-and-control server, so the victim never connects directly to the final destination. How can the relay affect monitoring?

Answer choices

  1. A. It removes the need for network addressing, for the described technical objective and its associated operational control requirements, in context.
  2. B. The proxy can obscure the final destination from sensors that only observe the victim's direct connection, for evaluation.
  3. C. It proves the final server is safe, as the recommended implementation across the complete governed service lifecycle.
  4. D. It prevents all endpoint telemetry, as the selected approach for the stated technical and business outcome.

Correct answer

The proxy can obscure the final destination from sensors that only observe the victim's direct connection, for evaluation.

Objective/domain: 2. Security Monitoring

Source: MITRE ATT&CK Enterprise

Question 8 Two servers built from the same approved image now differ because local administrators changed security settings over time. What problem is MOST clearly demonstrated?

Answer choices

  1. A. A false negative, as the recommended response to this scenario.
  2. B. Configuration drift from the approved baseline, as the organization’s selected response.
  3. C. A DNS delegation error, within the described context.
  4. D. A packet retransmission, for the stated scenario.

Correct answer

Configuration drift from the approved baseline, as the organization’s selected response.

Objective/domain: 5. Security Policies and Procedures

Source: NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations

Question 9 A process on a workstation tries to open an outbound TCP connection, but the local security log records a host-firewall rule blocking the connection before it leaves the endpoint. Which control generated the most directly relevant enforcement evidence?

Answer choices

  1. A. The upstream data-center firewall, for review.
  2. B. The SIEM correlation engine itself
  3. C. The host-based firewall, under the stated technical, operational, and governance constraints.
  4. D. The DNS registrar, within cross-functional operational-accountability boundaries.

Correct answer

The host-based firewall, under the stated technical, operational, and governance constraints.

Objective/domain: 3. Host-Based Analysis

Source: NIST SP 800-41 Rev. 1, Guidelines on Firewalls and Firewall Policy

Question 10 A NetFlow record confirms a long-lived HTTPS connection to a suspicious host but does not reveal the requested URI. Why can the URI not be determined from the flow record alone?

Answer choices

  1. A. HTTPS has no URIs, for the described technical objective and its associated operational control requirements, as configured.
  2. B. Source ports encode the requested path, as the recommended implementation across the complete governed service lifecycle.
  3. C. The destination IP always equals the full URL, under end-to-end security-and-governance requirements.
  4. D. Flow telemetry summarizes the conversation and does not preserve application payload content, for this task.

Correct answer

Flow telemetry summarizes the conversation and does not preserve application payload content, for this task.

Objective/domain: 4. Network Intrusion Analysis

Source: Cisco IOS XE Network Services Configuration Guide — Flexible NetFlow

Where to go after the daily web set

How are Cisco CyberOps Associate questions generated?

dotCreds builds Cisco CyberOps Associate practice questions from public exam objectives and Cisco exam and documentation references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start Cisco CyberOps Associate practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.