Skip to exam content
← All Exams
Techclick Infosec

Cisco 200-201 Practice Test

CyberOps Associate · 200-201 CBROPS

100 questions · 120 min · 82% Techclick practice target

100
Questions
120
Minutes
82%
Techclick Practice Target

⚠️ Exam Rules

  • Once started, the timer cannot be paused
  • You can navigate freely — use Previous or the Navigator panel to revisit any question
  • Tab-switching triggers warnings (3 strikes = auto-submit)
  • Right-click and copy disabled during exam
  • If you fail, retry — questions and options reshuffle

200-201 practice test: what's covered

Questions in this Techclick bank100
Timer120 min
Techclick practice target82%
Official exam code200-201

Free 200-201 sample questions

  1. A SOC analyst is asked to classify a control. A database administrator implements transparent data encryption (TDE) so disk theft does not expose customer records. Which CIA-triad pillar does this control PRIMARILY protect?

    • A. Confidentiality — TDE keeps data unreadable to anyone without the key
    • B. Integrity — TDE prevents the data from being modified
    • C. Availability — TDE keeps the database online during an attack
    • D. Non-repudiation — TDE signs each transaction
    Show answer

    Correct: A. Encryption-at-rest protects confidentiality. Integrity is provided by hashing/HMAC/digital signatures. Availability is provided by redundancy/clustering. The common trap (B) is conflating "tamper-proof storage" with "encrypted storage" — TDE does NOT detect modification; you would need hashing or signed audit logs for that.

  2. Which TWO of the following are correctly classified as part of an organization's ATTACK SURFACE? (Choose 2)

    • A. An internet-facing Citrix Netscaler with a public DNS record
    • B. A printed copy of the password policy locked in the CISO's desk
    • C. A USB port enabled on a domain-joined laptop allowed to leave the office
    • D. The internal name of the AD forest as known only to admins
    Show answer

    Correct: A and C. Attack surface = the sum of points where an attacker could attempt entry or extract data. Public-facing services and removable-media interfaces both qualify. The locked printed document and the internal forest name are not exposed entry points. The trap is thinking "internal-only info" is part of the attack surface — it is part of the threat MODEL, not surface.

  3. A vulnerability scan reports the following: <pre>CVE-2024-12345 Apache httpd 2.4.49 Path traversal CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Base: 9.8</pre> The asset is an internal Apache server with no internet exposure, behind a WAF that already blocks the exploit string. Which CVSS sub-score should you adjust to reflect THIS deployment?

    • A. Base score — re-calculate Base because the server is internal
    • B. Environmental score — Modified Attack Vector (MAV) and Modified scope reflect the deployment
    • C. Temporal score — set Exploit Code Maturity to High
    • D. Impact sub-score — lower the C/I/A metrics
    Show answer

    Correct: B. CVSS Base is a static, vendor-published score and should never be modified — it is the worst-case theoretical score. Temporal reflects the exploit/fix maturity over time. Environmental reflects YOUR deployment — MAV/MAC/MPR/MUI and the modified impact metrics let you downgrade an internet-exploitable bug to local-only. This is the #1 trap on CyberOps: analysts edit Base instead of Environmental.

  4. A threat-actor model categorises adversaries by motive and capability. A nation-state group conducts a multi-year intrusion targeting your aerospace IP via custom malware, zero-days, and supply-chain compromise. Which classification is BEST?

    • A. Script kiddie — using off-the-shelf tools
    • B. Advanced Persistent Threat (APT) — state-sponsored, long-dwell, custom TTPs
    • C. Hacktivist — politically motivated defacement
    • D. Insider — abuse of legitimate access
    Show answer

    Correct: B. APT = high capability + long dwell + strategic targeting. Script kiddies use existing tools and rarely persist. Hacktivists prioritise visibility (defacement, DDoS). Insider threats originate inside the trust boundary. The trap is calling any sophisticated attack "APT" — APT specifically implies a persistent campaign by a resourced (typically nation-state) group.

  5. A security architect is designing a multi-layered defense model for an enterprise network. Which TWO of the following security controls are correctly categorized as DETECTIVE controls? (Choose TWO)

    • A. Intrusion Detection System (IDS) monitoring network traffic for known attack signatures
    • B. SIEM correlation rules configured to alert on anomalous login attempts
    • C. Firewall rule blocking inbound access to port 22 from the public internet
    • D. Automated endpoint patch management software enforcing security updates
    Show answer

    Correct: A and B. Detective controls identify and alert on security threats or violations after or as they occur. Both an IDS monitoring network traffic and SIEM correlation rules alerting on failed logins act as detective controls. Firewalls and automated patch management serve as preventive controls designed to block attacks or remediate vulnerabilities before exploitation.

Last updated:

200-201 practice test FAQ

Is this 200-201 practice test free?

Yes. You can start, finish and score it for free, and download the Techclick practice certificate.

How many questions are in the Techclick 200-201 practice test?

This bank has 100 original scenario-based questions with a 120-minute timer and a 82% Techclick practice target.

What is the official exam code and format?

The official exam code is 200-201 (Cisco).

Are these real 200-201 exam questions or dumps?

No. They are original practice questions written by Techclick. This is not the vendor's official exam and not leaked dumps.

Do I get a certificate?

Score 82% or higher to get a Techclick practice certificate and LinkedIn badge. It is not an official Cisco certification.

What should I take after 200-201?

Related practice tests: CCIE Security Written 350-701, CCNA 200-301, Cisco 300-410, CCNP ENCOR 350-401, Cisco 100-160, Cisco 350-201 (linked below).

Techclick Infosec
TECHCLICK INFOSEC
CYBERSECURITY · PRACTICE ASSESSMENT
🛡️
PRACTICE ASSESSMENT
Cisco CyberOps
CyberOps Associate · 200-201 CBROPS
AWARDED TO
{NAME}
SCORE
0%
DATE
--
TC-200-201-XXX
Verified at exam.techclick.in · Techclick Infosec Pvt Ltd · +91 92772 29456