
CiscoCertified CyberOps Associate
Domain 5Objective 3
5.3 Apply the Incident Handling Process Such as NIST.SP800-61 to an Event 200-201 Practice Questions (Page 2)
Part of the 5.0 Security Policies and Procedures domain, which accounts for 15% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
8concepts
15%of the exam
Questions 6–10
- 6
According to NIST SP 800-61, which phase of the incident handling lifecycle involves developing policies, establishing response procedures, and preparing tools and resources before an incident occurs?
Select an answer first - 7
A SOC analyst receives an alert from the SIEM indicating a high volume of outbound traffic from a single workstation to a known command-and-control domain. The analyst also sees a user report that the workstation is running slowly. According to NIST SP 800-61, which phase of the incident handling lifecycle is the analyst currently in?
Select an answer first - 8
After resolving a security incident, the incident response team holds a meeting to discuss what went well and what could be improved. What is this activity called?
Select an answer first - 9
What is the primary purpose of documenting lessons learned after an incident?
Select an answer first - 10
A company's security team has confirmed that a server is infected with ransomware that is actively encrypting files. The server hosts a critical application that cannot be offline for more than 30 minutes. The team has a recent clean backup. Which containment strategy should the team choose to balance the need to stop the spread and the need to restore service quickly?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.