200-201 Sample Questions & Answers
Security monitoring data gets the heaviest weighting, alongside the CIA triad and attack-surface concepts, endpoint analysis of Windows and Linux components, mapping intrusion events to their source technology, and incident handling under NIST SP800-61.
Launch the full 200-201 simulator →Showing 10 of 20 free samples.
- Question 1
Which of the following describes a TCP injection attack?
Show answer & explanation
Correct answer: A
A TCP injection attack occurs when an attacker injects malicious data into legitimate TCP packets. The key indicator is multiple TCP SYN packets captured with identical sequence numbers, source and destination IP addresses, but different payloads - this shows someone is manipulating the packet contents. High volume scanning indicates reconnaissance activity, different IP addresses would suggest packet spoofing rather than injection, and slower actions indicate stealth techniques rather than injection attacks.
- Question 2
How are attributes of ownership and control of an object managed in Linux?
Show answer & explanation
Correct answer: A
Linux manages ownership and control of objects through a comprehensive permissions system. This includes file permissions (read, write, execute), ownership (user and group), and access control mechanisms. The permission system controls who can access files, directories, and system resources, and what actions they can perform. Rights is too general a term, while permissions specifically refers to the Linux access control framework that governs object ownership and control.
- Question 3
What is the standard for digital certificates?
Show answer & explanation
Correct answer: C
Explanation: The standard for digital certificates is X.509. These text documents include identifying information of the holder, the most important being the public key of the holder.
X.500 is the standards for directory services.
Power over Ethernet (PoE) is defined by the IEEE 802.3af and 802.3at standards. PoE allows an Ethernet switch to provide power to an attached device by applying power to the same wires in a UTP cable that are used to transmit and receive data. PoE+ is an enhanced version of PoE that provides more power and better reliability. PoE+ is most commonly deployed in enterprise networks, while PoE is usually sufficient for small business or home networks.
The IEEE 802.11 standard, which is the main standard for wireless LANs (WLANs), specifies using Carrier Sense Multiple Access/Collision Avoidance (CSMA/CA) for its media access method. Like an Ethernet network, which uses Carrier Sense Multiple Access/Collision Detection (CSMA/CD), wireless adapter cards “sense', or listen, for network traffic before transmitting. If the network is free of traffic, the station will send its data. The 802.22 standard also refers to CSMA/CA as Distributed Coordination Function (DCF).However, unlike an Ethernet network, wireless network cards cannot send and receive transmissions at the same time, which means that they cannot detect a collision. Instead, the sending station will wait for an acknowledgement packet (ACK) to be sent by the destination computer, verifying that the data was received. If, after a random amount of time, an acknowledgement has not been received, the sending station will retransmit the data.
Objective: CryptographySub-Objective: Describe these items in regards to SSL/TLS: Cipher-suite, X.509 certificates, Key exchange, Protocol version, PKCS -- Reference: https://searchsecurity.techtarget.com/definition/X509-certificate
- Question 4
Which of the following is used to validate and in some cases revoke certificates?
Show answer & explanation
Correct answer: A
Explanation: A public key infrastructure (PKI) contains software hardware and policies that allow digital certificates to be created, validated, or revoked. A digital signature provides integrity, authentication, and non-repudiation in electronic mail. A PKI typically consists of the following components: certificates, a key repository, a method for revoking certificates, and a method to evaluate a certificate chain, which security professionals can use to follow the possession of keys.
Pretty Good Privacy (PGP) is an email encryption system. PGP uses a web of trust to validate public key pairs. In a web of trust model, users sign their own key pairs. If a user wants to receive a file encrypted with PGP, the user must first supply the public key.
Post Office Protocol (POP) is a client email program. It is used to retrieve email from the email server.
Dynamic Host Configuration (DHCP) is a protocol that allows network administrators to centrally manage and automate the assignment of Internet Protocol (IP) addresses in an organization’s network. DHCP can automatically assign a new IP address when a computer is plugged into a different location on the network.
Objective: Cryptography
Sub-Objective: Describe the operation of a PKI
-- Reference: https://searchsecurity.techtarget.com/definition/PKI
- Question 5
Which of the following describes a timing attack?
Show answer & explanation
Correct answer: C
Explanation: Timing attacks are those in which operations carried out are done much slower than normal to keep the IPS or IDS from assembling the operation into a recognizable attack.
Performing actions faster than normal might even make it easier for the IPS or IDS to assemble the parts of the operation into a recognizable attack.
Delaying the attack will have no bearing how easily the IPS may or may not recognize the attack.
Attackers really have no way of recognizing or acting upon an opportune moment.
Objective: Attack MethodsSub-Objective: Describe these evasion methods: Encryption and tunneling, Resource exhaustion, Traffic fragmentation, Protocol-level misinterpretation, Traffic substitution and insertion, Pivot.
- Question 6
Your organization uses both the users location and the time of a day when assessing a connection
request.
What type of access control model is this?
Show answer & explanation
Correct answer: C
Explanation: This is an example of attribute-based access control (ABAC). In this model, attributes and their combinations are used to control access. There are several classes of attributes that might be included:
Role-based access control (RBAC) provides a specific set of rights and permission based on the job role assigned to the user.
Discretionary access control (DAC) prescribes that the owner of an asset (data) decides the sensitively of the resource and who has access.
Mandatory access control (MAC) creates clearance levels and assigns clearance levels to data assets and to users. Subjects (users) can only access levels to which they have been given clearance and those below.
Objective: Security Concepts
Sub-Objective: Compare and contrast these access control models: Discretionary access control, mandatory access control, Nondiscretionary access control
- Question 7
At what layer of the OSI model Internet Protocol (IP) operate?
Show answer & explanation
Correct answer: A
Explanation: Both IPv4 and IPv6 operate at the Network Layer 3 of the Open System Interconnection (OSI) model.
The TCP/IP suite of protocols includes Address Resolution Protocol (ARP), Internet Protocol (IP), Internet Control Message (ICMP), Internet Group Management Protocol (IGMP), Transmission Control Protocol (TCP), and User Datagram Protocol (UDP).The TCP/IP suite operates at Layer 2, Layer 3, and Layer 4 of the OSI model follows:Layer 2, Data Link: ARPLayer 3, Network: IP, ICMP, IGMP, ARPLayer 4, Transport: TCP, UDPThe TCP/IP suite operates at layer 2, and layer 3 of the TCP/IP model as follows:Layer 1, Link: ARPLayer 2, Internet: IP, ICMP, IGMP, ARPLayer 3, Transport: TCP, UDPObjective: Network ConceptsSub-Objective: Describe the operation of the following: IP, TCP, UDP, ICMP -- Reference: http://www.ciscopress.com/articles/article.asp?p=1757634seqNum=2
- Question 8
Which of the following is a compilation of routine procedures and operations that the system administrator or operator carries out?
Show answer & explanation
Correct answer: D
Explanation: A runbook is a compilation of routine procedures and operations that the system administrator or operator carries out. The runbook is typically divided into routine automated processes and routine manual processes. The effectiveness of a runbook can be measure by these metrics.
Mean time between failures (MTBF) is an estimate of the amount of time a piece of equipment will last and is usually determined by the equipment vendor or third party.
Mean time to repair by the equipment of the amount of time it will take to fix a piece of equipment and return it to production. The owner of the equipment usually determines this amount of time.
An agenda comprises items to be covered in a meeting.
A workflow describes the movement of a piece of work through a process from one operation to another.
While a script may a part of runbook, not all runbook operations are automated. Some are manual.
Objective: Security Concepts
Sun-Objective: Describe these terms. Threat actor, Runbook automation (RBA), Chain of custody (evidentiary), Reverse engineering, Sliding window anomaly detection, PII, PHI.
- Question 9
Which of the following occurs at Layer 7 of the OSI model?
Show answer & explanation
Correct answer: D
Explanation: Deep packet inspection is performed by application firewalls, which operate at layer 7 (the Application layer) of the OSI model. This is the examination of the actual data portion of the IP packet. An application firewall is typically integrated into another type of firewall to filter traffic that is traveling at the Application layer of the Open Systems Interconnection (OSI) model. An embedded firewall is typically implemented as a component of a hardware device, such as a switch or a router.
Stateful firewall operation occurs at Layer 3. This type of inspection monitors the TCP three-way handshake which occurs at Layer 3. Stateful firewalls, monitor the state of each TCP connection as well. When traffic is encountered, a stateful firewall first examines a packet to see if it is the result of a previous connection. Information about previous connections is maintained in the state table.
With a stateful firewall, a packet is allowed if it is a response to a previous connection. If the state table holds no information about the packet, the packet is compared to the access control list (ACL). Depending on the ACL, the packet will be forwarded to the appropriate host or dropped completely.
Packer filtering can be done based on IP addresses and port numbers. That means this type of filtering occurs at Layer 3 and 4.VLANs filter traffic by MAC addresses, and as such operate at Layer 2 of the OSI model.
Objective: Network ConceptsSub-Objective: Compare and contrast deep packet inspection with packet filtering and stateful firewall operation. -- Reference: http://bloggerspath.com/what-is-deep-packet-inspection-and-its-advantages-and-disadvantages/
- Question 10
What occurs when you allow specific executable files while denying all others?
Show answer & explanation
Correct answer: A
Explanation: When you whitelisting, you are creating a list of allowed applications while denying all others. Those approved applications are designated as whitelisted. These lists can also be used for domain name allowance with DNS. Several products are available that check for applications that are not on the whitelist, including attempts to install those applications. For example, the logs generated by the whitelisting product would tell you if someone had attempted to install a key logger.
When blacklisting, you create a list of denied applications while allowing all others. These lists can also be used for domain name blocking with DNS. Blacklisting is an allow by default concept, where all software is allowed to execute unless it is on the Deny List.
There is no form of filtering called redlisting or greylisting.
Objective: Security Monitoring
Sub-Objective: Describe these NextGen IPS event types: Connection event, Intrusion event, Host or endpoint event, Network discovery event, NetFlow event.
-- Reference: https://www.schneier.com/blog/archives/2011/01/whitelisting_vs.html
Ready for the real thing?
The full 200-201 simulator has every exam-style question, timed mode, and instant scoring.