CyberOps Associate Incident Response Questions

Cisco CyberOps Associate Practice Test 13

Cisco Certified CyberOps Associate

1 / 10

Which command in Linux lists current processes with associated PIDs?

2 / 10

A log shows repeated “403 Forbidden” messages followed by “200 OK” for the same user account. What might this indicate?

3 / 10

Which method is often used to exfiltrate data without detection?

4 / 10

What does the “Principle of Least Privilege” recommend?

5 / 10

What is the main purpose of red team exercises?

6 / 10

Which Cisco solution provides DNS-layer security to block malicious domains?

7 / 10

A phishing site looks identical to a company’s login page but uses a misspelled domain. What is this technique called?

8 / 10

Which tool is used to analyze packet captures in a GUI?

9 / 10

Which part of the MITRE ATT&CK framework involves an attacker gaining and maintaining remote access?

10 / 10

What is the main difference between IDS and IPS?

Your score is

The average score is 97%

0%