dc dotCreds
Cisco Certified Cybersecurity Associate (200-201 CCNACBR) Practice Test

Cisco CyberOps Associate Practice Test

Start today’s free 10-question Cisco CyberOps Associate set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 17, 2026, 11:07 AM CDT

Go Pro - One Time Unlock

Unlock the full 200-201 CCNACBR bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 Cisco CyberOps Associate questions

Use this Cisco CyberOps Associate practice test to review Cisco Certified Cybersecurity Associate. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective 3.4 Identify type of evidence used based on provided logs 3. Host-Based Analysis

A user says they saw an administrator near a workstation shortly before an unauthorized change, but no record directly shows that person performing the action. How should the statement BEST be characterized?

Concept tested:
Question 2 of 10
Objective 5.6 Describe forensic collection and evidence handling 5. Security Policies and Procedures

A live server may contain an attacker's in-memory process and active network connections that will disappear if the system is powered off. Disk evidence can be acquired afterward. What forensic principle should guide the collection order?

Concept tested:
Question 3 of 10
Objective 2.9 Describe evasion and obfuscation techniques 2. Security Monitoring

Malware connects to an external relay and has the relay communicate with the final command-and-control server, so the victim never connects directly to the final destination. How can the relay affect monitoring?

Concept tested:
Question 4 of 10
Objective 3.2 Describe operating system components in Windows and Linux 3. Host-Based Analysis

A Windows process running under a service account successfully writes to a protected configuration file even though the account was expected to be read-only. Which evidence should the analyst inspect FIRST to explain the authorization decision?

Concept tested:
Question 5 of 10
Objective 5.3 Apply the incident response process 5. Security Policies and Procedures

Containment is complete; responders eliminate identified malicious components and return validated systems to production. Which response activities are MOST directly represented?

Concept tested:
Question 6 of 10
Objective 2.2 Identify security data from technologies 2. Security Monitoring

The SOC needs to identify which internal hosts communicated with an external IP, the ports used, byte counts, and session timing, but full packet payloads were not retained. Which telemetry is MOST appropriate?

Concept tested:
Question 7 of 10
Objective 4.8 Interpret protocol header fields as related to intrusion analysis 4. Network Intrusion Analysis

A capture on a LAN shows destination MAC, source MAC, and EtherType before the network-layer header. Which protocol layer/header is being examined?

Concept tested:
Question 8 of 10
Objective 1.7 Describe terms as defined in CVSS 1. Security Concepts

A vulnerability in a sandboxed component allows code to affect resources governed by a different security authority outside that component's security boundary. Which CVSS v3.1 Base metric is MOST directly affected?

Concept tested:
Question 9 of 10
Objective 4.1 Identify data provided by network security technologies 4. Network Intrusion Analysis

A firewall event contains source IP, destination IP, source/destination ports, protocol, rule name, action=deny, and timestamp. Which field is MOST important for determining the firewall's enforcement decision?

Concept tested:
Question 10 of 10
Objective 1.3 Describe security terms 1. Security Concepts

The SOC receives a vetted external report containing adversary infrastructure, indicators of compromise, observed TTPs, confidence notes, and recommended detection actions. Which security term BEST describes this packaged information?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
200-201 CCNACBR Pro $4.99 one-time

Unlock all 200 Cisco CyberOps Associate questions, explanations, review tools, and exam-style practice.

50 Exam Practice Test $1.99 one-time

A 50-question 200-201 CCNACBR PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

Cybersecurity Access Bundle $6.99/month

Security, defensive analysis, and network security practice in one monthly unlock.

What’s includedSecurity+, CySA+, Certified Ethical Hacker, ISC2 CISSP, ISC2 CCSP, ISACA CISM, AWS Security Specialty, Cisco CyberOps Associate, CCNA

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full 200-201 CCNACBR bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily 200-201 CCNACBR practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily Cisco CyberOps Associate set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 A user says they saw an administrator near a workstation shortly before an unauthorized change, but no record directly shows that person performing the action. How should the statement BEST be characterized?

Answer choices

  1. A. Indirect evidence that may support the investigation but does not directly prove the system action
  2. B. Direct system evidence of the exact command
  3. C. A cryptographic integrity check
  4. D. A network 5-tuple

Correct answer

Indirect evidence that may support the investigation but does not directly prove the system action

Indirect evidence supports an inference rather than directly recording the technical act itself; it should be weighed with stronger direct and corroborative sources.

Wrong-answer review

  • B. Direct system evidence of the exact command: The witness statement is not a system record of the command.
  • C. A cryptographic integrity check: It does not verify evidence integrity like a hash.
  • D. A network 5-tuple: It is not network-flow metadata.

Extra learning features

Why candidates miss this

The temptation to select 'Direct system evidence of the exact command' is understandable because it seems like the most direct answer. However, the question specifically highlights the *lack* of direct evidence, emphasizing the need to interpret indirect information carefully. The decisive clue is the phrase 'does not directly prove the system action,' which forces the learner to recognize the limitations of the statement. Likely wrong answer: Direct system evidence of the exact command Review focus: NIST SP 800-86, Guide to Integrating Forensic Techniques into Incident Response

Question 2 A live server may contain an attacker's in-memory process and active network connections that will disappear if the system is powered off. Disk evidence can be acquired afterward. What forensic principle should guide the collection order?

Answer choices

  1. A. Always reboot before collecting anything
  2. B. Collect only screenshots
  3. C. Collect the most volatile relevant evidence first when it can be done safely and according to procedure
  4. D. Ignore memory because disk is easier to image

Correct answer

Collect the most volatile relevant evidence first when it can be done safely and according to procedure

Objective/domain: 5. Security Policies and Procedures

Source: NIST SP 800-86, Guide to Integrating Forensic Techniques into Incident Response

Question 3 Malware connects to an external relay and has the relay communicate with the final command-and-control server, so the victim never connects directly to the final destination. How can the relay affect monitoring?

Answer choices

  1. A. It removes the need for network addressing
  2. B. The proxy can obscure the final destination from sensors that only observe the victim's direct connection
  3. C. It proves the final server is safe
  4. D. It prevents all endpoint telemetry

Correct answer

The proxy can obscure the final destination from sensors that only observe the victim's direct connection

Objective/domain: 2. Security Monitoring

Source: MITRE ATT&CK Enterprise

Question 4 A Windows process running under a service account successfully writes to a protected configuration file even though the account was expected to be read-only. Which evidence should the analyst inspect FIRST to explain the authorization decision?

Answer choices

  1. A. The packet TTL and IP ID values
  2. B. The DNS resolver's cache age
  3. C. The process access token together with the file's DACL/permissions
  4. D. The server's TLS cipher preference

Correct answer

The process access token together with the file's DACL/permissions

Objective/domain: 3. Host-Based Analysis

Source: Microsoft Learn — Parts of the Access Control Model

Question 5 Containment is complete; responders eliminate identified malicious components and return validated systems to production. Which response activities are MOST directly represented?

Answer choices

  1. A. Reconnaissance and initial access
  2. B. Eradication/remediation and recovery
  3. C. Threat intelligence collection only
  4. D. Asset procurement only

Correct answer

Eradication/remediation and recovery

Objective/domain: 5. Security Policies and Procedures

Source: NIST SP 800-61 Rev. 2, Computer Security Incident Handling Guide

Question 6 The SOC needs to identify which internal hosts communicated with an external IP, the ports used, byte counts, and session timing, but full packet payloads were not retained. Which telemetry is MOST appropriate?

Answer choices

  1. A. NetFlow or equivalent flow records
  2. B. Full disk images
  3. C. Endpoint antivirus quarantine records only
  4. D. Source-code repository history

Correct answer

NetFlow or equivalent flow records

Objective/domain: 2. Security Monitoring

Source: Cisco IOS XE Network Services Configuration Guide — Flexible NetFlow

Question 7 A capture on a LAN shows destination MAC, source MAC, and EtherType before the network-layer header. Which protocol layer/header is being examined?

Answer choices

  1. A. TCP header
  2. B. DNS message
  3. C. X.509 certificate
  4. D. Ethernet frame header

Correct answer

Ethernet frame header

Objective/domain: 4. Network Intrusion Analysis

Source: Wireshark User's Guide

Question 8 A vulnerability in a sandboxed component allows code to affect resources governed by a different security authority outside that component's security boundary. Which CVSS v3.1 Base metric is MOST directly affected?

Answer choices

  1. A. Scope
  2. B. User Interaction
  3. C. Attack Vector
  4. D. Report Confidence

Correct answer

Scope

Objective/domain: 1. Security Concepts

Source: FIRST Common Vulnerability Scoring System v3.1 Specification

Question 9 A firewall event contains source IP, destination IP, source/destination ports, protocol, rule name, action=deny, and timestamp. Which field is MOST important for determining the firewall's enforcement decision?

Answer choices

  1. A. The action/disposition and matched rule
  2. B. The monitor resolution
  3. C. The user's browser theme
  4. D. The DNS SOA serial alone

Correct answer

The action/disposition and matched rule

Objective/domain: 4. Network Intrusion Analysis

Source: NIST SP 800-41 Rev. 1, Guidelines on Firewalls and Firewall Policy

Question 10 The SOC receives a vetted external report containing adversary infrastructure, indicators of compromise, observed TTPs, confidence notes, and recommended detection actions. Which security term BEST describes this packaged information?

Answer choices

  1. A. Vulnerability scan output
  2. B. Cyber threat intelligence
  3. C. Patch-management inventory
  4. D. Asset-discovery telemetry

Correct answer

Cyber threat intelligence

Objective/domain: 1. Security Concepts

Source: NIST SP 800-150, Guide to Cyber Threat Information Sharing

Where to go after the daily web set

How are Cisco CyberOps Associate questions generated?

dotCreds builds Cisco CyberOps Associate practice questions from public exam objectives and Cisco exam and documentation references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start Cisco CyberOps Associate practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.