CyberOps Associate · 200-201 CBROPS
100 questions · 120 min · 82% Techclick practice target
⚠️ Exam Rules
| Questions in this Techclick bank | 100 |
|---|---|
| Timer | 120 min |
| Techclick practice target | 82% |
| Official exam code | 200-201 |
A SOC analyst is asked to classify a control. A database administrator implements transparent data encryption (TDE) so disk theft does not expose customer records. Which CIA-triad pillar does this control PRIMARILY protect?
Correct: A. Encryption-at-rest protects confidentiality. Integrity is provided by hashing/HMAC/digital signatures. Availability is provided by redundancy/clustering. The common trap (B) is conflating "tamper-proof storage" with "encrypted storage" — TDE does NOT detect modification; you would need hashing or signed audit logs for that.
Which TWO of the following are correctly classified as part of an organization's ATTACK SURFACE? (Choose 2)
Correct: A and C. Attack surface = the sum of points where an attacker could attempt entry or extract data. Public-facing services and removable-media interfaces both qualify. The locked printed document and the internal forest name are not exposed entry points. The trap is thinking "internal-only info" is part of the attack surface — it is part of the threat MODEL, not surface.
A vulnerability scan reports the following: <pre>CVE-2024-12345 Apache httpd 2.4.49 Path traversal CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Base: 9.8</pre> The asset is an internal Apache server with no internet exposure, behind a WAF that already blocks the exploit string. Which CVSS sub-score should you adjust to reflect THIS deployment?
Correct: B. CVSS Base is a static, vendor-published score and should never be modified — it is the worst-case theoretical score. Temporal reflects the exploit/fix maturity over time. Environmental reflects YOUR deployment — MAV/MAC/MPR/MUI and the modified impact metrics let you downgrade an internet-exploitable bug to local-only. This is the #1 trap on CyberOps: analysts edit Base instead of Environmental.
A threat-actor model categorises adversaries by motive and capability. A nation-state group conducts a multi-year intrusion targeting your aerospace IP via custom malware, zero-days, and supply-chain compromise. Which classification is BEST?
Correct: B. APT = high capability + long dwell + strategic targeting. Script kiddies use existing tools and rarely persist. Hacktivists prioritise visibility (defacement, DDoS). Insider threats originate inside the trust boundary. The trap is calling any sophisticated attack "APT" — APT specifically implies a persistent campaign by a resourced (typically nation-state) group.
A security architect is designing a multi-layered defense model for an enterprise network. Which TWO of the following security controls are correctly categorized as DETECTIVE controls? (Choose TWO)
Correct: A and B. Detective controls identify and alert on security threats or violations after or as they occur. Both an IDS monitoring network traffic and SIEM correlation rules alerting on failed logins act as detective controls. Firewalls and automated patch management serve as preventive controls designed to block attacks or remediate vulnerabilities before exploitation.
Last updated:
Yes. You can start, finish and score it for free, and download the Techclick practice certificate.
This bank has 100 original scenario-based questions with a 120-minute timer and a 82% Techclick practice target.
The official exam code is 200-201 (Cisco).
No. They are original practice questions written by Techclick. This is not the vendor's official exam and not leaked dumps.
Score 82% or higher to get a Techclick practice certificate and LinkedIn badge. It is not an official Cisco certification.
Related practice tests: CCIE Security Written 350-701, CCNA 200-301, Cisco 300-410, CCNP ENCOR 350-401, Cisco 100-160, Cisco 350-201 (linked below).

You earned it — let the world know!
