Free 200-201 Practice Test Questions and Answers (2026)
Q: 1
What is a benefit of using asymmetric cryptography?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 2
What is a difference between rule-based and role-based access control mechanisms?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 3
Refer to the exhibit.
Which frame numbers contain a file that is extractable via TCP stream within Wireshark?
Which frame numbers contain a file that is extractable via TCP stream within Wireshark?Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 4
Which evasion method involves performing actions slower than normal to prevent detection?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 5
Which two elements of the incident response process are stated in NIST Special Publication 800-61
r2? (Choose two.)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 6
A threat actor penetrated an organization's network. Using the 5-tuple approach, which data points
should the analyst use to isolate the compromised host in a grouped set of logs?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 7
When an event is investigated, which type of data provides the investigate capability to determine if
data exfiltration has occurred?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 8
A company is using several network applications that require high availability and responsiveness,
such that milliseconds of latency on network traffic is not acceptable. An engineer needs to analyze
the network and identify ways to improve traffic movement to minimize delays. Which information
must the engineer obtain for this analysis?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 9
A security consultant must change the identity access management model fof their organization The
new approach will put responsibility on the owner, who will decide whichusers will have access to
which resources Which low-cost model must be used for this purpose?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 10
Refer to the exhibit.
What is shown in this PCAP file?
What is shown in this PCAP file?Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 11
Which type of access control depends on the job function of the user?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 12
An organization has recently adjusted its security stance in response to online threats made by a
known hacktivist group.
What is the initial event called in the NIST SP800-61?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 13
An engineer is working with the compliance teams to identify the data passing through the network.
During analysis, the engineer informs the compliance team that external penmeter data flows
contain records, writings, and artwork Internal segregated network flows contain the customer
choices by gender, addresses, and product preferences by age. The engineer must identify protected
dat
a. Which two types of data must be identified'? (Choose two.)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 14
Which items is an end-point application greylist used?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 15
Refer to the exhibit.
A network administrator is investigating suspicious network activity by analyzing captured traffic. An
engineer notices abnormal behavior and discovers that the default user agent is present in the
headers of requests and data being transmitted What is occurring?
A network administrator is investigating suspicious network activity by analyzing captured traffic. An
engineer notices abnormal behavior and discovers that the default user agent is present in the
headers of requests and data being transmitted What is occurring?Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 16
Which regular expression is needed to capture the IP address 192.168.20.232?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 17
What is the difference between vulnerability and risk?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 18
Which two elements are assets in the role of attribution in an investigation? (Choose two.)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 19
DRAG DROP Refer to the exhibit. 
Drag & Drop
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 20
DRAG DROP Drag and drop the access control models from the left onto the correct descriptions on the right.
Drag & Drop
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 20

