Easy 200-201 practice questions
Direct recall — confirm you know the core facts and definitions. 17 easy questions available — no sign-up, always free.
A SOC analyst is building a dashboard and wants to include a data source that provides human-readable notifications generated when traffic matches predefined signatures or rules, each including a rule ID, classification, and severity. Which type of security monitoring data best matches this description?
An e-commerce company's public web application becomes unreachable for two hours during a peak sales event. Investigation reveals a volumetric flood of traffic that saturated the server's bandwidth. No data was stolen, altered, or exposed. Which element of the CIA triad was primarily compromised in this incident?
A sales employee's laptop is stolen from a parked car. The device contained an unencrypted spreadsheet with customer names, addresses, and credit card numbers. During the incident review, the security team is asked which principle of the CIA triad was most directly violated when the thief could read the customer data from the drive. Which principle applies?
A SOC analyst reviews an alert during a service outage. The company's public web server is unreachable, and NetFlow data shows an overwhelming volume of inbound HTTP requests arriving simultaneously from more than 40,000 unique source IP addresses spread across dozens of countries. Server CPU and bandwidth are fully saturated. Which type of attack best matches these observations?
A SOC analyst reviews an alert from an intrusion detection system that flagged inbound traffic to a web server as an active SQL injection attack. After investigation, the analyst confirms the traffic was a legitimate scheduled scan by the organization's authorized vulnerability assessment tool, and no actual malicious activity occurred. How should this alert be classified?
A financial services company discovers that database records showing customer account balances were silently altered by an attacker who gained write access. The data remained available and no unauthorized parties viewed it, but the recorded values no longer match the actual transactions. Which element of the CIA triad was primarily violated in this incident?
A SOC analyst reviews an endpoint alert: multiple user document files on a workstation had their extensions changed to '.locked', and a text file named 'RECOVER_FILES.txt' now sits in every affected folder demanding Bitcoin payment for a decryption key. Based on these observed behaviors, which type of endpoint-based attack is MOST likely occurring?
During a security review, an analyst reads the following log line: 'Threat detected: Win32/Emotet in C:\Users\jsmith\Downloads\invoice.exe — Action taken: Quarantined. Signature version 1.389.204.0.' The analyst must map this event to the correct source technology so it can be correlated with other data. Which source technology most likely produced this event?
A SOC analyst receives a data feed showing records with source IP, destination IP, source and destination ports, protocol number, byte counts, packet counts, and start/end timestamps for each conversation — but no application-layer payload. The feed originates from the organization's edge router. When mapping this event data to its source technology, which technology most likely produced these records?
Following a ransomware outbreak, an incident response team has removed the malware, rebuilt affected systems, and confirmed normal operations have resumed. The team now holds a meeting to document what happened, evaluate how well their procedures worked, and identify improvements to detection tooling and staff training. According to the NIST SP 800-61 incident response lifecycle, which phase does this meeting represent?
A newly hired CyberOps analyst is reviewing the organization's incident response program, which is modeled on NIST SP 800-61. She notices that before any incident occurs, the team has already deployed a centralized log aggregation platform, created jump bags with forensic tools, established out-of-band communication channels, and trained staff on their roles. Which phase of the NIST incident response life cycle do these activities belong to?
During a data classification review, a SOC analyst is cataloging the types of protected data traversing the corporate network. The engineering team stores proprietary source code, patented product design schematics, and internal research documents on a shared server. Which category of protected data best describes these assets?
During a data-classification review, a CyberOps analyst captures a database export traversing the internal network. The record set contains employee full names paired with Social Security numbers, home addresses, and dates of birth. According to standard data-protection categories, how should this data be classified?
A SOC analyst reviews an endpoint alert showing a user process rapidly reading, encrypting, and rewriting thousands of files across mapped network drives, followed by the creation of a text file named 'RECOVER_YOUR_FILES.txt' in every affected directory. The Volume Shadow Copy service was also stopped just before the encryption began. Which type of endpoint-based attack does this behavior most clearly indicate?
A SOC analyst reviews an IDS alert that fired for outbound traffic to a known malicious IP. After investigating the endpoint, the analyst confirms the host is running a trojan that was beaconing to the flagged IP. How should this alert be classified?
A finance employee receives a phone call from someone claiming to be from the company's IT help desk. The caller states there is an urgent security incident and asks the employee to read back the one-time passcode that was just texted to their phone so IT can 'verify the account.' The employee complies, and minutes later notices unauthorized logins to their account. Which type of attack does this scenario BEST describe?
During a host investigation on a Windows workstation, an analyst needs to examine the hierarchical database that stores configuration settings for the operating system, installed applications, user profiles, and hardware. Which operating system component should the analyst inspect?