Free Cisco Certified CyberOps Associate practice — 6 questions on Security Concepts, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Security Concepts
A vulnerability has been scored with the following CVSS v3.1 base vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Which statement correctly interprets this vector?
AV:N (network), AC:L (low complexity), PR:N (no privileges required), UI:N (no user interaction), and C:H/I:H/A:H (high impact to all three CIA properties) together describe a remotely exploitable, unauthenticated attack with total impact on confidentiality, integrity, and availability.
Question 2 of 6 · Security Concepts
A SOC analyst reviews endpoint forensics and confirms that malware successfully executed and exfiltrated data from a host, but the IPS produced no alert for this activity at the time it occurred. How should this event be classified?
Malicious activity actually occurred, but the detection system failed to alert on it. This mismatch between reality (malicious) and detection (no alert) is the definition of a false negative.
Question 3 of 6 · Security Concepts
Which statement best distinguishes an Indicator of Attack (IOA) from an Indicator of Compromise (IOC) in threat analysis?
IOAs are behavior-based and intent-focused, enabling detection of an attack in progress before full compromise, whereas IOCs are static, after-the-fact artifacts (hashes, IPs, domains) confirming a compromise already occurred.
Question 4 of 6 · Security Concepts
A government facility processes classified information at multiple sensitivity levels (Confidential, Secret, Top Secret). Users must not be able to grant access to files they own, and access decisions must be enforced centrally based on security labels assigned to both subjects and objects. Which access control model BEST satisfies this requirement?
MAC enforces access centrally using classification labels (e.g., clearance levels) assigned to subjects and objects, and explicitly removes the ability of resource owners to grant access at their own discretion, matching all stated requirements.
Question 5 of 6 · Security Concepts
An organization identifies two vulnerabilities on an internet-facing web server. Vulnerability 1 has a high likelihood of exploitation but very low impact if exploited. Vulnerability 2 has a low likelihood of exploitation but catastrophic impact (complete data loss) if exploited. Using the standard risk determination approach where Risk = Likelihood x Impact, which statement is MOST accurate?
The risk formula treats likelihood and impact as multiplicative factors; a high value in one factor does not automatically outweigh a low value in the other without actually calculating the product, so ranking requires quantifying both.
Question 6 of 6 · Security Concepts
A SOC identifies that a Linux server exposes SSH, FTP, and an unused legacy SNMP v1 service to the internet. Only SSH, restricted to a jump host's IP address, is required for the server's function. Which action provides the GREATEST reduction in attack surface for this server?
Attack surface reduction means eliminating unnecessary exposed services and access paths entirely; disabling unused FTP/SNMP and restricting SSH to a single trusted source removes attack vectors rather than merely monitoring or inspecting them.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.