Cisco CCNA Cybersecurity (200-201 CCNACBR) · Domain 1 · 20% of exam

Security Concepts

Drill 20 practice questions focused entirely on Security Concepts for the Cisco 200-201 exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.

Verified answer20 questions
Question 1 of 20

A defense contractor requires that every file and user be assigned a sensitivity label (e.g., Confidential, Secret, Top Secret), and the operating system itself enforces that a user can only open a file if their clearance dominates the file's label. Individual data owners are NOT permitted to grant other users access to their own files. Which access control model is being described?

Reviewed for accuracy · Report an issue
Question 2 of 20

A security analyst is tasked with monitoring workloads that a development team spins up and tears down in a public cloud environment. The workloads are ephemeral virtual instances that may exist for only minutes before being terminated. The analyst notices that by the time an alert is investigated, the instance is often already gone, leaving no host to examine. Which characteristic of cloud environments is MOST responsible for this data visibility challenge?

Reviewed for accuracy · Report an issue
Question 3 of 20

A remote employee successfully logs into the corporate VPN using a valid username, password, and a token from their authenticator app. After connecting, they attempt to open a shared folder containing HR payroll files but receive an 'access denied' message, even though their credentials were accepted. Which pair of security concepts best explains what succeeded and what failed in this situation?

Reviewed for accuracy · Report an issue
Question 4 of 20

An e-commerce company's public web application becomes unreachable for two hours during a peak sales event. Investigation reveals a volumetric flood of traffic that saturated the server's bandwidth. No data was stolen, altered, or exposed. Which element of the CIA triad was primarily compromised in this incident?

Reviewed for accuracy · Report an issue
Question 5 of 20

A security architect is planning endpoint monitoring for a fleet of company laptops that frequently leave the corporate network and connect from home and public Wi-Fi. Management requires continuous telemetry, local process inspection, and the ability to enforce policy even when a device is offline from the corporate LAN. Which deployment approach best satisfies these requirements?

Reviewed for accuracy · Report an issue
Question 6 of 20

A network security engineer is asked to deploy a sensor that must actively block malicious packets before they reach internal servers, without relying on a separate device to drop the traffic afterward. The sensor will be placed directly in the path of live traffic between the perimeter firewall and the server farm. Which security deployment does this describe?

Reviewed for accuracy · Report an issue
Question 7 of 20

A sales employee's laptop is stolen from a parked car. The device contained an unencrypted spreadsheet with customer names, addresses, and credit card numbers. During the incident review, the security team is asked which principle of the CIA triad was most directly violated when the thief could read the customer data from the drive. Which principle applies?

Reviewed for accuracy · Report an issue
Question 8 of 20

A vulnerability analyst is scoring a newly disclosed flaw using CVSS v3.1. The vendor advisory notes that successful exploitation requires the attacker to first win a race condition and rely on a specific memory layout that varies between systems, meaning the attacker cannot control conditions and must repeatedly attempt the attack. Which base metric value best reflects this characteristic?

Reviewed for accuracy · Report an issue
Question 9 of 20

A vulnerability analyst is reviewing a newly disclosed flaw in a public-facing web application. The flaw can be triggered by any remote attacker sending a crafted HTTP request over the internet, without any authentication and without any user interaction. When completing the CVSS v3.1 base metrics for this finding, which value should the analyst assign to the Attack Vector (AV) metric?

Reviewed for accuracy · Report an issue
Question 10 of 20

A SOC analyst is scoring a newly disclosed web application vulnerability using CVSS v3.1. The vulnerability allows an unauthenticated attacker to modify arbitrary records in the backend database, but it does not expose any data to the attacker and does not disrupt the availability of the service. Which base metric should the analyst rate as High for this vulnerability?

Reviewed for accuracy · Report an issue
Question 11 of 20

A vulnerability analyst is scoring a newly disclosed flaw in an internal web application. Exploitation requires the attacker to first authenticate to the application using a standard, non-administrative user account before triggering the vulnerable function. Which CVSS base metric value most accurately reflects this condition?

Reviewed for accuracy · Report an issue
Question 12 of 20

A security analyst is reviewing a CVSS v3.1 vector for a vulnerability in a hypervisor. Exploiting a guest virtual machine allows an attacker to affect resources belonging to the host operating system and other VMs beyond the initially compromised guest. Which CVSS base metric specifically captures this situation where the exploited component and the impacted component are different security authorities?

Reviewed for accuracy · Report an issue
Question 13 of 20

A security analyst is scoring a newly disclosed vulnerability in a document viewer. Exploitation only succeeds if a victim opens a malicious file that is emailed to them; the code will not run on its own. Which CVSS base metric value most accurately captures this condition?

Reviewed for accuracy · Report an issue
Question 14 of 20

A SOC analyst reviewing outbound traffic profiles notices a workstation generating an unusually high volume of DNS TXT record queries to a single external domain over several hours. Total DNS traffic from this host is many times the baseline, though no large file transfers appear over HTTP or FTP. Which potential data loss concern does this traffic profile most likely indicate?

Reviewed for accuracy · Report an issue
Question 15 of 20

A SOC analyst reviewing NetFlow records notices that a workstation in the finance department, which normally generates only small bursts of outbound traffic, has been sending 4 GB of data over the course of one night to an unfamiliar external IP address on TCP port 443. The internal file server it accessed contains sensitive customer records. Based on this traffic profile, what does this activity most likely indicate?

Reviewed for accuracy · Report an issue
Question 16 of 20

A security architect is documenting the layers of a defense-in-depth strategy for a new office. She wants to categorize each control by type. The company enforces a written acceptable use policy that all employees must sign, requires badge readers at every door, and runs endpoint antivirus on all workstations. When classifying the signed acceptable use policy, which category of security control does it represent?

Reviewed for accuracy · Report an issue
Question 17 of 20

A security architect is reviewing a new deployment. An attacker who phished a user's credentials was still unable to move laterally because network segmentation blocked traffic to critical servers, and endpoint detection quarantined the malware that was dropped. The architect wants to describe the security principle that allowed multiple independent controls to compensate when the first control (user awareness) failed. Which principle best describes this design?

Reviewed for accuracy · Report an issue
Question 18 of 20

A software development team uses a shared Linux file server where each developer can set read, write, and execute permissions on the files they create and can grant those permissions to any other user at their own discretion. A security analyst reviewing this arrangement needs to classify the access control model in use. Which model best describes this behavior?

Reviewed for accuracy · Report an issue
Question 19 of 20

A SOC analyst is reviewing traffic captured at the network perimeter to hunt for command-and-control activity. She notices that over 80% of outbound sessions are TLS-encrypted, and her intrusion detection sensor can no longer inspect the payloads of these sessions for malicious signatures. Which data visibility challenge is she primarily facing?

Reviewed for accuracy · Report an issue
Question 20 of 20

A financial services company discovers that database records showing customer account balances were silently altered by an attacker who gained write access. The data remained available and no unauthorized parties viewed it, but the recorded values no longer match the actual transactions. Which element of the CIA triad was primarily violated in this incident?

Reviewed for accuracy · Report an issue

More 200-201 practice

Keep going with the other Cisco CCNA Cybersecurity (200-201 CCNACBR) domains, or take a full timed mock exam.

← Back to 200-201 overview