Security Monitoring for Cisco CyberOps Associate (CBROPS 200-201)
This page covers the Security Monitoring domain of the Cisco CyberOps Associate (CBROPS 200-201) certification. Master Cybersecurity offers 45 practice questions in this domain, drawn from the same content we use across our timed exam simulations. Below are five sample questions with full answer explanations.
Sample Practice Questions
Question 1
What is rule-based detection when compared to statistical detection?- A. proof of a user's identity
- B. proof of a user's action
- C. likelihood of user's action
- D. falsification of a user's identity
Explanation
The correct answer is: B. proof of a user's action.
Rule-based detection, also called signature-based detection, compares observed activity against explicitly written patterns that change only when an operator edits them, so a hit is deterministic: the event either matched the rule or it did not. That gives the analyst proof that a particular action took place, such as a specific exploit string being sent or a forbidden command being executed. Statistical detection is the opposite model, building a numerical baseline of normal behaviour and scoring deviation from it, so its output is only the likelihood that activity is abnormal rather than a certainty, which is why it yields more false positives and needs analyst judgement. Neither method establishes who a person is, so proving identity is the job of authentication and identity systems rather than of a detection engine. Falsification of identity describes spoofing or credential theft performed by the attacker, which is a technique that detection tries to catch rather than a property of a detection method.
Question 2
Which process is used when IPS events are removed to improve data integrity?- A. data availability
- B. data normalization
- C. data signature
- D. data protection
Explanation
The correct answer is: B. data normalization.
Data normalisation is the stage of event processing where records from different sources are converted into a common format and redundant or duplicate entries are removed, which is what raises data integrity: afterwards each real occurrence is represented once, fields such as addresses, ports and timestamps carry the same meaning across sources, and correlation and reporting are no longer skewed by the same intrusion prevention event being counted several times. Data availability describes whether information can be reached when it is needed, one leg of the confidentiality, integrity and availability triad, and says nothing about deduplicating records. A data signature is a pattern used to recognise known malicious content, or a cryptographic value used to verify that data has not been altered, rather than a process that prunes an event set. Data protection is the broad umbrella of controls such as encryption, access control and backup that guard information against loss or disclosure, again not the specific cleanup step that removes duplicate events from a feed.
Question 3
An analyst is investigating an incident in a SOC environment. Which method is used to identify a session from a group of logs?- A. sequence numbers
- B. IP identifier
- C. 5-tuple
- D. timestamps
Explanation
The correct answer is: C. 5-tuple.
The 5-tuple is the combination of source address, source port, destination address, destination port and transport protocol, and because that set uniquely names one conversation it is the pivot an analyst uses to pull every record belonging to the same session out of a mixed pile of logs. Firewall permits, proxy requests, flow records, intrusion alerts and packet captures all carry those five fields, so filtering each source on the same tuple reconstructs one connection end to end across tools that otherwise share nothing. Sequence numbers exist only inside a single TCP stream, are relative to that connection and are absent from most log formats, so they order bytes within a session rather than identify which session a record belongs to. The IP identifier helps reassemble the fragments of one datagram and is far too narrow and reused to distinguish sessions. Timestamps are essential for building a timeline, but many unrelated sessions occur in the same instant, so time alone cannot separate one session from another.
Question 4
What is a difference between SOAR and SIEM?- A. SOAR platforms are used for threat and vulnerability management, but SIEM applications are not
- B. SIEM applications are used for threat and vulnerability management, but SOAR platforms are not
- C. SOAR receives information from a single platform and delivers it to a SIEM
- D. SIEM receives information from a single platform and delivers it to a SOAR
Explanation
The correct answer is: A. SOAR platforms are used for threat and vulnerability management, but SIEM applications are not.
A SIEM collects logs from many sources, normalises them into a consistent format, correlates events, and raises alerts, and that is essentially where its job ends. SOAR builds on top of that with orchestration and automation: case management, playbooks that execute response actions without an analyst clicking through them, and threat and vulnerability management workflows. So SOAR platforms are used for threat and vulnerability management while SIEM applications are not, and the reverse claim inverts the relationship between the two product classes. Both statements about receiving information from a single platform are wrong on their face, because neither tool is single-source: a SIEM is defined by ingesting from many devices at once, and SOAR likewise pulls from the SIEM, ticketing systems, threat intelligence feeds, and endpoint tools. If anything the flow runs in the other direction, with SIEM alerts feeding a SOAR platform that then orchestrates the response.
Question 5
What is the difference between deep packet inspection and stateful inspection?- A. Deep packet inspection is more secure than stateful inspection on Layer 4
- B. Stateful inspection verifies contents at Layer 4 and deep packet inspection verifies connection at Layer 7
- C. Stateful inspection is more secure than deep packet inspection on Layer 7
- D. Deep packet inspection allows visibility on Layer 7 and stateful inspection allows visibility on Layer 4
Explanation
The correct answer is: D. Deep packet inspection allows visibility on Layer 7 and stateful inspection allows visibility on Layer 4.
Stateful inspection tracks connections using Layer 3 and Layer 4 information, keeping a session table so it can tell that a returning segment belongs to a flow the client legitimately opened, but it does not read the application content being carried. Deep packet inspection goes further and parses the payload itself, so it can identify the application protocol, extract fields such as HTTP headers or DNS names, and match on content, which is Layer 7 visibility. The real distinction is therefore the depth of the layer each technique can see, not one being generically more secure than the other, so the claims that deep inspection is more secure at Layer 4 or that stateful inspection is more secure at Layer 7 both mislabel where each method works. The wording that has stateful inspection verifying contents at Layer 4 and deep packet inspection verifying connections at Layer 7 reverses the two roles, because verifying content is the payload-reading job and tracking connections is the state-table job.
Other Cisco CyberOps Associate (CBROPS 200-201) domains
- Host-Based Analysis (31 questions)
- Network Intrusion Analysis (35 questions)
- Security Concepts (47 questions)
- Security Policies and Procedures (12 questions)