Cisco CyberOps Associate CBROPS 200-201 Practice Test

所在平台: Udemy

课程主页: https://www.udemy.com/course/cisco-cyberops-associate-cbrops-200-201-practice-test/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:思科网络安全运营助理 CBROPS 200-201 练习测试 课程概述:本课程旨在帮助未来的网络安全分析师,为理解思科网络安全运营基础(CBROPS)考试作准备。CBROPS 考试为期 120 分钟,包含 95 至 105 道题目,覆盖网络安全事件的防止、检测、分析和响应的基础知识。持有网络安全运营助理认证的个人能为安全运营中心(SOC)相关职位铺平道路。尽管 200-201 CBROPS 考试没有先决条件,但学生需要具备网络和网络安全概念的基础知识。本练习测试包含了考试的各个领域的内容,帮助您顺利通过考试。 测试内容包括以下几个领域: 1. 安全概念(20%) - CIA三元组、各种安全部署的比较、安全术语的描述、防御深度策略的原则、访问控制模型的比较以及数据可见性带来的挑战等。 2. 安全监控(25%) - 比较攻击面与漏洞、描述网络攻击(如拒绝服务、SQL 注入、社会工程等),以及识别数据在安全监控中的用途。 3. 主机分析(20%) - 描述端点技术在安全监控中的功能、操作系统组件的识别、证据类型的比较以及操作系统和应用程序日志的解析等。 4. 网络侵入分析(20%) - 映射事件与来源技术、比较深度包检测与状态防火墙、解析 PCAP 文件及 Wireshark 的实际应用等。 5. 安全政策与程序(15%) - 管理概念的描述、事件响应计划的元素、基于 NIST.SP800-61 的事件处理过程等。 本课程为希望进入网络安全领域的学习者提供了必备的理论与实践能力,是顺利通过 CBROPS 考试的良好准备。

课程评论(0条)

课程详情

The Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS) exam is a 120-minute exam that includes 95 to 105 questions. This exam and curriculum are designed to prepare the cybersecurity analysts of the future! The CyberOps Associate certification provides a path to prepare individuals pursuing a cybersecurity career and associate-level job roles in security operations centers (SOCs). The exam covers the fundamentals you need to prevent, detect, analyze, and respond to cybersecurity incidents.There are no prerequisites for the 200-201 CBROPS exam; however, students must have an understanding of networking and cybersecurity concepts.This practice test help you to pass the exam. The contents of this test cover each of the domains represented in the exam.1- Security Concepts (20%) - Describe the CIA triad - Compare security deployments - Describe security terms - Compare security concepts - Describe the principles of the defense-in-depth strategy - Compare access control models - Describe terms as defined in CVSS - Identify the challenges of data visibility (network, host, and cloud) in detection - Identify potential data loss from provided traffic profiles - Interpret the 5-tuple approach to isolate a compromised host in a grouped set of logs - Compare rule-based detection vs. behavioral and statistical detection 2- Security Monitoring (25%) - Compare attack surface and vulnerability - Identify the types of data provided by these technologies - Describe the impact of these technologies on data visibility - Describe the uses of these data types in security monitoring - Describe network attacks, such as protocol-based, denial of service, distributed denial of service, and man-in-the-middle - Describe web application attacks, such as SQL injection, command injections, and cross-site scripting - Describe social engineering attacks - Describe endpoint-based attacks, such as buffer overflows, command and control (C2), malware, and ransomware - Describe evasion and obfuscation techniques, such as tunneling, encryption, and proxies - Describe the impact of certificates on security (includes PKI, public/private crossing the network, asymmetric/symmetric) - Identify the certificate components in a given scenario3- Host-based Analysis (20%) - Describe the functionality of these endpoint technologies in regard to security monitoring - Identify components of an operating system (such as Windows and Linux) in a given scenario - Describe the role of attribution in an investigation - Identify type of evidence used based on provided logs - Compare tampered and untampered disk image - Interpret operating system, application, or command line logs to identify an event - Interpret the output report of a malware analysis tool (such as a detonation chamber or sandbox)4- Network Intrusion Analysis (20%) - Map the provided events to source technologies - Compare impact and no impact for these items - Compare deep packet inspection with packet filtering and stateful firewall operation - Compare inline traffic interrogation and taps or traffic monitoring - Compare the characteristics of data obtained from taps or traffic monitoring and transactional data (NetFlow) in the analysis of network traffic - Extract files from a TCP stream when given a PCAP file and Wireshark - Identify key elements in an intrusion from a given PCAP file - Interpret the fields in protocol headers as related to intrusion analysis - Interpret common artifact elements from an event to identify an alert5- Security Policies and Procedures (15%) - Describe management concepts - Describe the elements in an incident response plan as stated in NIST.SP800-61 - Apply the incident handling process (such as NIST.SP800-61) to an event - Map elements to these steps of analysis based on the NIST.SP800-61 - Map the organization stakeholders against the NIST IR categories (CMMC, NIST.SP800-61) - Describe concepts as documented in NIST.SP800-86 - Identify these elements used for network profiling - Identify these elements used for server profiling - Identify protected data in a network - Classify intrusion events into categories as defined by security models, such as Cyber Kill Chain Model and Diamond Model of Intrusion - Describe the relationship of SOC metrics to scope analysis (time to detect, time to contain, time to respond, time to control)

课程标签

0人关注该课程

主题相关的课程