Security Concepts for Cisco CyberOps Associate (CBROPS 200-201)
This page covers the Security Concepts domain of the Cisco CyberOps Associate (CBROPS 200-201) certification. Master Cybersecurity offers 47 practice questions in this domain, drawn from the same content we use across our timed exam simulations. Below are five sample questions with full answer explanations.
Sample Practice Questions
Question 1
Which event is user interaction?- A. gaining root access
- B. executing remote code
- C. reading and writing file permission
- D. opening a malicious file
Explanation
The correct answer is: D. opening a malicious file.
User Interaction is the CVSS exploitability metric that asks whether a human other than the attacker must take some action for an exploit to succeed, so opening a malicious file is the event it describes: the vulnerability cannot fire until the victim double-clicks the attachment or the document, which is why such flaws score lower than ones an attacker triggers alone. Gaining root access is an outcome of exploitation and relates to the privileges the attacker ends up holding, not to any action a user performs. Executing remote code is likewise a result, and a remotely exploitable service flaw is the classic example of a vulnerability requiring no user interaction at all. Reading and writing file permission describes access rights on an object and maps more closely to the Privileges Required metric, which measures the level of access an attacker needs before launching the attack rather than participation by a victim.
Question 2
What is a benefit of agent-based protection when compared to agentless protection?- A. It lowers maintenance costs
- B. It provides a centralized platform
- C. It collects and detects all traffic locally
- D. It manages numerous devices simultaneously
Explanation
The correct answer is: C. It collects and detects all traffic locally.
The benefit unique to agent-based protection is that it collects and detects activity locally on the endpoint. Because software runs on the host itself, it observes process creation, file and registry changes, user actions, and the traffic entering and leaving that machine, giving depth of visibility no network vantage point can match. It also keeps working when the endpoint leaves the corporate network, so a laptop on a home or hotel connection is still monitored and still enforcing policy. The other advantages listed belong to agentless deployment, which is exactly the trade-off being tested: with no software to install there is nothing to package, deploy, or update on each host, so maintenance costs are lower, one console can reach large numbers of devices, and management is centralised without touching the endpoints. Agentless collection, however, is limited to what is observable from the network or through remote interfaces, which is why it cannot supply the local process-level detail an agent provides.
Question 3
One of the objectives of information security is to protect the CIA of information and systems. What does CIA mean in this context?- A. confidentiality, identity, and authorization
- B. confidentiality, integrity, and authorization
- C. confidentiality, identity, and availability
- D. confidentiality, integrity, and availability
Explanation
The correct answer is: D. confidentiality, integrity, and availability.
CIA is the shorthand for the three foundational goals of information security: confidentiality, integrity, and availability. Confidentiality keeps data readable only by those authorised to see it and is enforced with encryption and access controls, integrity guarantees that data has not been altered and is verified with hashing and digital signatures, and availability ensures systems are reachable when needed and is protected with redundancy and denial of service mitigation. Nearly every incident can be mapped to which of the three was affected, which is why the triad runs through security frameworks. Answers that substitute identity for integrity or availability confuse identification, the claim of who a subject is, with the protection goals themselves. Substituting authorization for availability confuses the granting of permissions with the guarantee that a resource can be reached at all. Identification, authentication, authorization, and accounting are supporting mechanisms, the means by which confidentiality and integrity get enforced rather than members of the triad.
Question 4
What is the difference between mandatory access control (MAC) and discretionary access control (DAC)?- A. MAC is controlled by the discretion of the owner and DAC is controlled by an administrator
- B. MAC is the strictest of all levels of control and DAC is object-based access
- C. DAC is controlled by the operating system and MAC is controlled by an administrator
- D. DAC is the strictest of all levels of control and MAC is object-based access
Explanation
The correct answer is: B. MAC is the strictest of all levels of control and DAC is object-based access.
Mandatory access control is the strictest model because the system rather than the user enforces the policy: objects carry sensitivity labels, subjects carry clearances, and the operating system compares them on every access, so even a file's creator cannot hand out rights the policy forbids. Discretionary access control leaves permissions to the discretion of the object owner, who edits the access control list on each object; that owner-per-object control is what the phrase object-based access captures, and it is how ordinary file permissions on Windows and Unix behave. The choice that reverses the two, claiming discretionary control comes from an administrator while mandatory control follows the owner's discretion, inverts the defining property of each model. Saying discretionary control is enforced by the operating system while mandatory control comes from an administrator is likewise backwards, and calling discretionary control the strictest contradicts the fact that owners can freely delegate access under it.
Question 5
What is the practice of giving employees only those permissions necessary to perform their specific role within an organization?- A. least privilege
- B. need to know
- C. integrity validation
- D. due diligence
Explanation
The correct answer is: A. least privilege.
Giving employees only the permissions their specific role demands is least privilege, a foundational access control principle holding that every account and process should run with the minimum rights necessary and nothing more. It applies to service accounts and applications as much as to people, which is why well-designed software avoids running with administrative rights it does not need and drops privileges as soon as it can. Need to know is narrower and information-centric: it limits who may see a particular piece of data or classified material, and it is normally layered on top of least privilege rather than replacing it. Integrity validation is not an access concept at all; it uses hashes, checksums, or digital signatures to prove that data has not been altered. Due diligence is a governance and risk term covering the reasonable investigation an organization performs before accepting a risk or engaging a vendor. Only least privilege describes scoping permissions to a role.
Other Cisco CyberOps Associate (CBROPS 200-201) domains
- Host-Based Analysis (31 questions)
- Network Intrusion Analysis (35 questions)
- Security Monitoring (45 questions)
- Security Policies and Procedures (12 questions)