Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS) 試験
最新更新時間: 2026/09/21
【秋学習応援セール|10月限定キャンペーン】:200-201 最新真題を買う時、日本語版と英語版両方を同時に獲得できます。
実際の問題集を練習し、試験のポイントを了解し、テストに申し込むするかどうかを決めることができます。
さらに試験準備時間の35%を節約するには、200-201 問題集を使用してください。
Question No : 1
DRAG DROP
Drag and drop the access control models from the left onto the correct descriptions on the right.

正解: 
Question No : 2
At which layer is deep packet inspection investigated on a firewall?
正解:
Explanation:
Deep packet inspection (DPI) is a sophisticated method of examining the content of data packets as they pass through a network checkpoint, including both the header and the data payload. DPI is typically performed at the application layer of the Open Systems Interconnection (OSI) model. This allows the inspection process to evaluate the actual content of the packets, not just the header information, enabling the identification of various types of threats and the enforcement of network policies1.
Reference: = The explanation aligns with the information provided by Digital Guardian, which details how DPI works and at which layer it is applied1.
Question No : 3
What should a security analyst consider when comparing inline traffic interrogation with traffic tapping to determine which approach to use in the network?
正解:
Explanation:
Traffic tapping involves replicating network traffic and sending it to a separate port where it can be analyzed without affecting the original traffic flow. This allows security analysts to monitor and analyze traffic for potential threats without the risk of blocking legitimate traffic.
Reference: This explanation is based on general network security concepts, as the current page does not provide specific Cisco documentation.
Question No : 4
Which event artifact is used to identify HTTP GET requests for a specific file?
正解:
Explanation:
The Uniform Resource Identifier (URI) is used to identify specific resources on the internet, including files. In the context of HTTP GET requests, the URI specifies the path to the file being requested.
Reference: This explanation is based on standard web protocols and practices, as the current page does not provide specific Cisco documentation.
Question No : 5
Which HTTP header field is used in forensics to identify the type of browser used?
正解:
Explanation:
The user-agent HTTP header field is used in forensics to identify the type of browser used. It contains a characteristic string that allows network protocol peers to identify the operating system and browser of the web-server. This information is crucial in forensic analysis as it can provide insights into the client’s environment1.
Reference: = The importance of the user-agent string in identifying the browser type is discussed in various technical resources, including the Wikipedia page on HTTP header fields2 and articles on GeeksforGeeks1.
Question No : 6
Which two pieces of information are collected from the IPv4 protocol header? (Choose two.)
正解:
Explanation:
The IPv4 protocol header contains various fields that provide essential information for routing and delivery of packets across an IP network. Two key pieces of information collected from the IPv4 header are the source IP address and the destination IP address of the packet. These addresses are crucial for identifying where a packet is coming from and where it is intended to go12.
Reference: = The structure and fields of the IPv4 header, including the source and destination IP addresses, are explained in detail in networking resources and documentation, such as the Computer Networking Notes tutorial on IPv4 Header Structure1, and the Engineering LibreTexts on the IPv4 Header2.
Question No : 7
Which signature impacts network traffic by causing legitimate traffic to be blocked?
正解:
Explanation:
A false positive in network security is when a benign action is incorrectly flagged as malicious, leading to legitimate traffic being blocked. This can disrupt normal network operations and access to services, as the security system mistakenly identifies normal behavior as a threat1.
Reference: = The concept of false positives and their impact on network traffic is discussed in various cybersecurity resources, including Cisco’s own training materials and discussions on network security best practices1.
Question No : 8
An analyst discovers that a legitimate security alert has been dismissed.
Which signature caused this impact on network traffic?
正解:
Explanation:
A false negative occurs when an intrusion detection system (IDS) fails to detect and report actual malicious activity. This means that a legitimate security alert has been dismissed or overlooked, allowing potentially harmful traffic to pass through the network undetected. The impact of false negatives can be significant as they represent missed opportunities to stop or mitigate security threats1.
Reference: = Cisco documentation on security systems, such as IPS (Intrusion Prevention System), discusses the importance of accurately detecting malicious activity and the risks associated with false negatives, which include the failure to trigger alerts for actual attacks1.
Question No : 9
Which type of data collection requires the largest amount of storage space?
正解:
Explanation:
Full packet capture requires the largest amount of storage space because it involves recording all packets that pass through a network, including all headers and payloads. This type of data collection is comprehensive and allows for detailed analysis, but due to the volume of data it encompasses, it demands significant storage capacity1.
Reference: = The Cisco Secure Network Analytics Data Store Design Guide discusses the storage requirements for different types of network data collection, highlighting the substantial storage needs for full packet captures1.
Question No : 10
Refer to the exhibit.

What is the expected result when the "Allow subdissector to reassemble TCP streams" feature is enabled?
正解:
Explanation:
Enabling the “Allow subdissector to reassemble TCP streams” feature in Wireshark allows the tool to reassemble TCP segments into a contiguous sequence, which can be used by higher-level protocols to reconstruct a full message, such as an HTTP request or response. This is particularly useful for extracting files or data transmitted over TCP that are spread across multiple packets1.
Reference: = The explanation is based on the Wireshark documentation, which details how the reassembly feature works and its use in analyzing TCP streams
Question No : 11
DRAG DROP
Refer to the exhibit.

Drag and drop the element name from the left onto the correct piece of the PCAP file on the right.

正解: 
Explanation:
In a PCAP file, which is used to capture network packets, each packet contains various pieces of information that can be analyzed. The source and destination addresses refer to the IP addresses of the sender and receiver of the packets. The source and destination ports refer to the port numbers used for the communication, with common ports like 443 indicating HTTPS traffic. The network protocol here is TCP, which is responsible for establishing a connection and ensuring the delivery of packets. The transport protocol is IPv4, which is the underlying protocol for routing packets across the network. Lastly, the application protocol is TLS v1.2, which is used for secure communication over the internet.
Reference: = The Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS) course material covers the analysis of network traffic and the interpretation of PCAP files, which includes identifying the different elements within a packet capture1.
Question No : 12
Refer to the exhibit.

Which application protocol is in this PCAP file?
正解:
Explanation:
The PCAP file in the exhibit shows a Transmission Control Protocol (TCP) communication between two IP addresses. In the data section of the packet capture, “pdy/3.1… http/1” is visible, indicating that HTTP (Hypertext Transfer Protocol) is being used as the application protocol for this communication.
Reference: = The Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS) course material covers the analysis of network traffic using tools like packet analyzers to identify application protocols in use1.
Question No : 13
Which evasion technique is indicated when an intrusion detection system begins receiving an abnormally high volume of scanning from numerous sources?
正解:
Explanation:
Resource exhaustion is an evasion technique where an attacker overwhelms a system with a high volume of requests from multiple sources. This can cause the system to become overloaded and unable to process legitimate traffic, potentially allowing the attacker to bypass security measures like intrusion detection systems.
Reference: = The answers are based on the knowledge from the Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS) course material, which covers various cybersecurity concepts, including file identification methods, application control technologies, firewall utilities, and evasion techniques
Question No : 14
Which utility blocks a host portscan?
正解:
Explanation:
A host-based firewall is a utility that can block unauthorized access to a computer system, including port scans. It monitors incoming and outgoing network traffic and permits or blocks data packets based on a set of security rules.
Question No : 15
A security engineer deploys an enterprise-wide host/endpoint technology for all of the company's corporate PCs. Management requests the engineer to block a selected set of applications on all PCs.
Which technology should be used to accomplish this task?
正解:
Explanation:
Application whitelisting/blacklisting is a technology used to control which applications are allowed to execute on a company’s corporate PCs. Whitelisting allows only approved applications to run, while blacklisting prevents specific applications from running. This approach is effective for managing application usage across an enterprise.