
CiscoCertified CyberOps Associate
Domain 5Objective 3
5.3 Apply the Incident Handling Process Such as NIST.SP800-61 to an Event 200-201 Practice Questions (Page 3)
Part of the 5.0 Security Policies and Procedures domain, which accounts for 15% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
8concepts
15%of the exam
Questions 11–15
- 11
During an active incident, the incident response team lead instructs a team member to document every action taken, including timestamps, who performed the action, and the outcome. Why is this documentation critical during the incident?
Select an answer first - 12
An analyst receives an alert from an intrusion detection system (IDS) about suspicious network traffic. What is the primary purpose of analyzing this alert in the context of incident handling?
Select an answer first - 13
Which of the following is the best example of a security incident rather than just a security event?
Select an answer first - 14
After a major incident, the incident response team conducts a post-incident review. The team finds that the incident was not detected for 48 hours because the monitoring tool was not configured to alert on the specific type of activity. Which recommendation should the team include in the lessons learned report?
Select an answer first - 15
A security analyst is reviewing logs and finds that a user's account was used to access a sensitive file at 2:00 AM, which is outside the user's normal working hours. The analyst also sees that the user's account has been locked out multiple times in the past hour. The user is on vacation and has not been active. Which classification best describes this situation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.