Network Intrusion Analysis for Cisco CyberOps Associate (CBROPS 200-201)
This page covers the Network Intrusion Analysis domain of the Cisco CyberOps Associate (CBROPS 200-201) certification. Master Cybersecurity offers 35 practice questions in this domain, drawn from the same content we use across our timed exam simulations. Below are five sample questions with full answer explanations.
Sample Practice Questions
Question 1
Which evasion technique is a function of ransomware?- A. extended sleep calls
- B. encryption
- C. resource exhaustion
- D. encoding
Explanation
The correct answer is: B. encryption.
Ransomware exists to make data unreadable to its owner, and encryption is the mechanism that does it, so encryption is the function tied to that family. It also defeats defenders analytically, because encrypted files and encrypted command-and-control channels give an inspection device no plaintext to match a signature against, and strong encryption cannot be reversed without the key. Extended sleep calls are a sandbox-evasion trick used broadly across malware to outlast an automated analysis window, but delaying execution is not what defines ransomware. Resource exhaustion is aimed at a monitoring sensor, burying it under more traffic or state than it can process so real activity goes unlogged, which is a sensor-evasion tactic rather than a payload behavior. Encoding schemes such as base64, hexadecimal, or URL escaping only change how bytes are represented and are trivially reversible by any analyst or dissector, so they conceal far less than encryption and lock nobody out of their files.
Question 2
When trying to evade IDS/IPS devices, which mechanism allows the user to make the data incomprehensible without a specific key, certificate, or password?- A. fragmentation
- B. pivoting
- C. encryption
- D. stenography
Explanation
The correct answer is: C. encryption.
Encryption is the mechanism that renders data incomprehensible without a specific key, certificate, or password, which is exactly why it is such an effective way to evade signature-based inspection. When an attacker tunnels traffic inside TLS or another encrypted channel, the intrusion detection or prevention sensor still sees packets but cannot read the payload, so content signatures never match and the sensor is reduced to inspecting metadata such as addresses, ports, and certificate fields. Steganography is a different concealment technique: it hides the existence of data inside an innocuous carrier such as an image or audio file, and the hidden content requires no key or credential to read once it has been located. Fragmentation evades detection by splitting a payload across multiple packets so that no single packet contains the full signature, relying on reassembly differences rather than on making data unreadable. Pivoting is a lateral-movement technique in which an attacker routes activity through an already-compromised host, changing where traffic appears to originate rather than obscuring its content.
Question 3
What is the difference between the ACK flag and the RST flag in the NetFlow log session?- A. The RST flag confirms the beginning of the TCP connection, and the ACK flag responds when the data for the payload is complete
- B. The ACK flag confirms the beginning of the TCP connection, and the RST flag responds when the data for the payload is complete
- C. The RST flag confirms the receipt of the prior segment, and the ACK flag allows for the spontaneous termination of a connection
- D. The ACK flag confirms the receipt of the prior segment, and the RST flag allows for the spontaneous termination of a connection
Explanation
The correct answer is: D. The ACK flag confirms the receipt of the prior segment, and the RST flag allows for the spontaneous termination of a connection.
TCP flags have fixed meanings that flow records preserve. The ACK flag acknowledges data, confirming that bytes up to the acknowledgment number were received, and it is set on nearly every segment once the handshake is complete. The RST flag tears a connection down immediately and unilaterally with no exchange of closing segments, which is how a stack rejects traffic to a closed port and how either side aborts an established session, so RST is what permits spontaneous termination. That makes ACK as receipt confirmation and RST as abrupt termination the correct pairing. The answers that place RST at the beginning of a connection are wrong because a connection opens with SYN, is answered with SYN-ACK, and is completed with a final ACK, and a RST in that position aborts the attempt instead of establishing it. The statements that describe either flag as signalling that payload data is complete also miss, since orderly completion and graceful closure are signalled by FIN.
Question 4
How is NetFlow different from traffic mirroring?- A. NetFlow collects metadata and traffic mirroring clones data.
- B. Traffic mirroring impacts switch performance and NetFlow does not.
- C. Traffic mirroring costs less to operate than NetFlow.
- D. NetFlow generates more data than traffic mirroring.
Explanation
The correct answer is: A. NetFlow collects metadata and traffic mirroring clones data..
NetFlow summarizes conversations rather than copying them: the device records metadata such as source and destination addresses, ports, protocol, interface, timestamps, byte and packet counts, and TCP flags, then exports those flow records to a collector. Traffic mirroring instead clones the actual frames through a SPAN session or a tap and delivers full packets, payload included, to a sensor. That difference in fidelity is the defining one, which is why the accurate statement is that NetFlow collects metadata while traffic mirroring clones data. The claim that only mirroring taxes switch performance is misleading, because flow accounting also consumes switch CPU and memory and is not free. Cost comparisons run the other way in practice, since mirroring requires sensor and storage capacity sized to the full packet rate while flow records are far cheaper to move and keep. For the same reason mirroring generates far more data than NetFlow, not less, so choosing NetFlow is a deliberate trade of payload visibility for scale and retention.
Question 5
Refer to the exhibit. What is occurring in this network?- A. ARP cache poisoning
- B. DNS cache poisoning
- C. MAC address table overflow
- D. MAC flooding attack
Explanation
The correct answer is: A. ARP cache poisoning.
ARP carries no authentication, so any host can announce that an IP address belongs to its own MAC address, and the fingerprint of that abuse is ARP replies nobody solicited or two different MAC addresses claiming the same IP inside a short window, which analyzers surface as a duplicate address warning. The effect is that victims rebind a gateway or peer IP to the attacker MAC and hand their traffic to the attacker, so unsolicited or conflicting ARP replies point to ARP cache poisoning. DNS cache poisoning works a layer up on name resolution, planting forged answers for domain names in a resolver cache, and its evidence is DNS responses rather than ARP frames. A MAC address table overflow floods a switch with a large number of fabricated source MAC addresses until the switching table fills and frames get flooded out every port; a MAC flooding attack is that same technique named for its behavior. Both would show volumes of unique bogus source addresses rather than one IP being rebound to a new MAC.
Other Cisco CyberOps Associate (CBROPS 200-201) domains
- Host-Based Analysis (31 questions)
- Security Concepts (47 questions)
- Security Monitoring (45 questions)
- Security Policies and Procedures (12 questions)