Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 5Objective 3

5.3 Apply the Incident Handling Process Such as NIST.SP800-61 to an Event 200-201 Practice Questions (Page 6)

Part of the 5.0 Security Policies and Procedures domain, which accounts for 15% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)

29questions here
6free pages
8concepts
15%of the exam

Questions 26–29

  1. 26foundation · easy

    In an incident response team, which role is typically responsible for coordinating the response efforts and ensuring that the team follows the incident handling process?

    Select an answer first
  2. 27application · medium

    A security team is responding to a ransomware incident. The team has isolated the affected systems and is now preparing to eradicate the malware. Which action is part of the Eradication phase?

    Select an answer first
  3. 28foundation · easy

    Which activity is part of the recovery phase after an incident has been eradicated?

    Select an answer first
  4. 29foundation · easy

    During an incident, a security team decides to isolate an infected workstation from the network. Which containment strategy does this action represent?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to 200-201

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.